⚠️ Region Alert: UAE/Middle East
Unit 42 has uncovered a persistent cyberespionage campaign tracked as CL-STA-1114, which overlaps with activities attributed to the Russian threat actor Void Blizzard (LAUNDRY BEAR). The campaign targets Zimbra Collaboration Suite (ZCS) webmail servers across critical sectors, including government, defense, and finance, primarily in NATO countries, Ukraine, and Africa. The attackers utilize a sophisticated zero-click phishing technique leveraging CVE-2025-66376 to inject malicious JavaScript without requiring any user interaction.
Once the exploit is triggered, a JavaScript payload exfiltrates highly sensitive information, including login credentials, CSRF tokens, 2FA scratch codes, and up to 90 days of email and search history. Security analysts have identified multiple command-and-control (C2) domains and IP addresses associated with the infrastructure. Organizations using Zimbra are urged to apply patches immediately and monitor for the provided indicators of compromise to defend against this evolving state-sponsored threat.
Top comments (0)