Russian Espionage Campaign Targets Zimbra Webmail with Zero-Click Exploits
A Russian cyberespionage campaign, tracked as CL-STA-1114 and attributed to the Void Blizzard/LAUNDRY BEAR threat actor, is actively exploiting a zero-day vulnerability in Zimbra Collaboration Suite (ZCS) to steal sensitive user credentials and data.

A sophisticated cyberespionage campaign, identified by Unit 42 as CL-STA-1114 and linked to Russian threat actors known as Void Blizzard and LAUNDRY BEAR, has been actively targeting organizations globally. The campaign specifically focuses on exploiting vulnerabilities within the Zimbra Collaboration Suite (ZCS) webmail platform to facilitate espionage activities. This operation has been ongoing since at least 2024, with the targeted exploitation of Zimbra beginning in July 2025.
The primary targets of this campaign include government entities, defense contractors, transportation companies, and financial organizations. Geographically, the attackers are focusing on NATO member states, Ukraine, Commonwealth of Independent States (CIS) countries, and nations across Africa. The objective is to gain access to sensitive information stored within compromised email accounts, including credentials, historical communications, and search data.
A unique and concerning aspect of this campaign is its reliance on zero-click phishing emails. These emails exploit a vulnerability in ZCS, identified as CVE-2025-66376, which allows for the automatic injection of a malicious JavaScript payload without any user interaction. This means that simply receiving and opening an email with the malicious HTML content can lead to compromise, significantly lowering the barrier for attackers.
Upon execution, the injected JavaScript payload exfiltrates a wide range of sensitive user data to hard-coded command and control (C2) servers. This data includes critical items such as Cross-Site Request Forgery (CSRF) tokens, email addresses and passwords, two-factor authentication (2FA) scratch codes, system and environment details, and the victim's email and search history from the past 90 days. The payload has shown minimal changes throughout the observed campaign, indicating a stable and effective exploit.
The attack chain begins with a phishing email containing either an HTML attachment or embedded HTML within the message body. These lures are often designed to appear as legitimate news headlines to capture the recipient's attention. The HTML code contains an obfuscated section, typically Base64-encoded, which, when processed by the browser, decodes and injects the JavaScript payload. This payload then silently communicates with the attacker's C2 infrastructure.
Unit 42 has identified at least nine distinct IP addresses and nine domains used as C2 servers throughout the campaign, with an average operational lifespan of approximately 35.4 days per server. The continuous use of these servers highlights the persistent nature of the threat actors and their efforts to maintain their infrastructure.
Palo Alto Networks emphasizes the critical need for organizations to remain vigilant, prioritize patching vulnerable ZCS instances, and implement advanced threat detection measures. Products like Cortex Advanced Email Security and Advanced URL Filtering can help mitigate these threats by analyzing suspicious attachments and blocking malicious domains. The Cyber Threat Alliance is also sharing this intelligence to enable rapid deployment of protections across member organizations.
This campaign underscores the evolving tactics of state-sponsored cyberespionage groups, who are increasingly targeting widely-used platforms like Zimbra to maximize their impact. The reliance on zero-click exploits and the exfiltration of extensive user data present a significant risk to critical industries worldwide, necessitating robust security postures and proactive defense strategies.
This NCSC advisory expands on the previously reported campaign by LAUNDRY BEAR, detailing the specific 'beehive' (or 'Ulej') exploit technique. It clarifies that the zero-click vulnerability affects Zimbra Collaboration Suite (ZCS) webmail and requires no user interaction beyond viewing a malicious email. The advisory also highlights that the threat actors extensively trialled these methods on Ukrainian victims before targeting NATO members, and notes the potential role of AI in developing the exploit's codebase.
This CISA alert provides further details on the ongoing campaign by LAUNDRY BEAR (also tracked as CL-STA-1114 and Void Blizzard) targeting Zimbra Collaboration Suite (ZCS). It highlights the use of a novel zero-day exploit, CVE-2025-66376, which allows for email exfiltration and persistent access simply by viewing a malicious email. The advisory also lists a broad coalition of international agencies endorsing its findings and recommendations.