CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian State-Supported Malicious Threat Activity
U.S. agencies warn of Russian state-backed hackers exploiting a zero-click flaw in Zimbra Collaboration Suite to steal email data from Western organizations, including government and defense entities.
The Cybersecurity and Infrastructure Security Agency (CISA), NSA, FBI, and partners issued a joint advisory detailing a phishing campaign by the Russian APT group LAUNDRY BEAR targeting Zimbra Collaboration Suite (ZCS) users. The campaign uses a zero-click exploit requiring only that a user views a malicious email in a vulnerable ZCS version, bypassing traditional phishing tactics. The advisory highlights the use of a custom tool called Ulej to exploit CVE-2025-66376 and potentially others, enabling data exfiltration without user interaction.
Since July 2025, over 10 organizations using ZCS have been compromised, with attackers stealing sensitive data such as email addresses, passwords, and two-factor authentication tokens. Targeted sectors include the Defense Industrial Base, federal and local governments, law enforcement, technology, education, media, and non-governmental organizations. The advisory provides mitigations and remediation steps to harden ZCS deployments against this activity.
CISA Acting Executive Assistant Director for Cybersecurity Chris Butera emphasized the growing sophistication of nation-state cyber threats, urging organizations to update ZCS software and monitor email services for malicious activity. The FBI’s Assistant Director Brett Leatherman noted that Russian state-sponsored actors have long targeted critical infrastructure, and this advisory aims to help defenders detect and counter such operations.
The advisory follows recent disclosures of LAUNDRY BEAR’s activities, which have focused on extracting configuration data from poorly secured routers. Organizations are advised to implement the recommended mitigations immediately to reduce exposure to this and similar threats. Further details on nation-state cyber threats are available on CISA’s website.