DEV Community

Mark0
Mark0

Posted on

Russian Global Webmail Espionage

⚠️ Region Alert: UAE/Middle East

Unit 42 has uncovered a persistent cyberespionage campaign tracked as CL-STA-1114, which overlaps with activities attributed to the Russian threat actor Void Blizzard (LAUNDRY BEAR). The campaign targets Zimbra Collaboration Suite (ZCS) webmail servers across critical sectors, including government, defense, and finance, primarily in NATO countries, Ukraine, and Africa. The attackers utilize a sophisticated zero-click phishing technique leveraging CVE-2025-66376 to inject malicious JavaScript without requiring any user interaction.

Once the exploit is triggered, a JavaScript payload exfiltrates highly sensitive information, including login credentials, CSRF tokens, 2FA scratch codes, and up to 90 days of email and search history. Security analysts have identified multiple command-and-control (C2) domains and IP addresses associated with the infrastructure. Organizations using Zimbra are urged to apply patches immediately and monitor for the provided indicators of compromise to defend against this evolving state-sponsored threat.


Read Full Article

Top comments (0)