INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Russian Espionage Group Exploits Zimbra to Steal Sensitive Data
| 2026-07-23 17:33 CRITICAL HIGHExecutive Summary AI-generated
Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries has been gaining momentum since July 2025. The state-sponsored threat group, also known as Void Blizzard, has compromised governments and organizations in defense, education, energy, law enforcement, media, finance, transportation and technology sectors through a novel exploit in popular Linux-based enterprise software. Officials warn that the covert nature of this activity and lack of financial extortion indicate involvement by Russian government backing. The threat group's tactics include stealing data via Zimbra Collaboration Suite instances with an unpatched vulnerability, targeting Ukrainian users first as a priority, and using phishing emails to deliver custom JavaScript payloads.
Technical Mitigations AI-generated
* Implement a patch for CVE-2025-66376 in all vulnerable Zimbra Collaboration Suite instances to prevent exploitation by Laundry Bear and Void Blizzard.
* Use email security solutions that include anti-phishing filters, such as Microsoft Defender Advanced Threat Protection (ATP) or Symantec Cloud Antivirus, to block zero-click phishing emails from Russian threat actors like Laundry Bear and Void Blizzard.
* Regularly update and patch all software applications, including Zimbra Collaboration Suite, to ensure that known vulnerabilities are addressed before they can be exploited by attackers.
* Implement a web application firewall (WAF) with advanced threat protection capabilities, such as those offered by F5 Networks or Cisco WebApp Firewall, to detect and block malicious traffic from Laundry Bear and Void Blizzard.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-66376CVE-2025-66376
Target & Sectors
NORDICS
NORDICS
BENELUX
BENELUX
MIDDLE_EAST
MIDDLE_EAST
EUROPE
EUROPE
CIS
CIS
NORTH_AMERICA
NORTH_AMERICA
AFRICA
AFRICA
defensedefense
transportationtransportation
energyenergy
educationeducation
mediamedia
financefinance
technologytechnology
governmentgovernment
Incident Timeline
July 2025
Russian state-sponsored threat actors used a novel exploit in popular Linux-based enterprise software to steal sensitive data from Western countries.
Click on any entity below to view its context and source!
source_region
Russian Federation
A Russian state-sponsored threat group has been stealing sensitive data from governments and commercial organizations since July 2025 via a novel exploit in popular Linux-based enterprise software, U.S. authorities and cyber officials from more than a dozen other countries warned in a
joint cybersecurity advisory
Thursday.
infrastructure
Linux
A Russian state-sponsored threat group has been stealing sensitive data from governments and commercial organizations since July 2025 via a novel exploit in popular Linux-based enterprise software, U.S. authorities and cyber officials from more than a dozen other countries warned in a
joint cybersecurity advisory
Thursday.
organisation
Technical Analysis
Technical Analysis
The attackers behind CL-STA-1114 have been active
since at least 2024
, and this campaign targeting Zimbra servers started in July 2025.
organisation
CL-STA-1114
Technical Analysis
The attackers behind CL-STA-1114 have been active
since at least 2024
, and this campaign targeting Zimbra servers started in July 2025.
November 2025
Russian espionage group used the Zimbra exploit to steal sensitive data from Western countries.
Click on any entity below to view its context and source!
tactic
Espionage
Laundry Bear’s most recent espionage campaign involves the exploitation of a zero-day vulnerability in Zimbra Collaboration Suite that wasn’t patched until November 2025, five months after attacks were well underway, officials said.
organisation
Laundry Bear’s
Laundry Bear’s most recent espionage campaign involves the exploitation of a zero-day vulnerability in Zimbra Collaboration Suite that wasn’t patched until November 2025, five months after attacks were well underway, officials said.
organisation
NATO
“Additionally, extensive Ukrainian targeting, prior to use against U.S. and other NATO allies, outlines an increasing trend within Russian cyber threat groups to target Ukrainian users first—both as a priority target and as a testbench for malicious cyber techniques before broader global deployment.”
organisation
Laundry Bear
Once a target is identified, Laundry Bear also likely compiles email addresses for users to target with the exploit via phishing emails.
infrastructure
6.1
The defect’s medium-severity rating of 6.1 underscores the challenge defenders regularly confront in prioritizing patching schedules based on measure of severity alone.
2026/07/23
Russian espionage group used novel Zimbra exploit to steal sensitive data from Western countries.
Click on any entity below to view its context and source!
organisation
Laundry Bear
This activity cluster overlaps with activity from a Russian threat actor tracked by other vendors as Void Blizzard and LAUNDRY BEAR.
organisation
NATO
The attackers behind this campaign targeted Zimbra webmail in organizations in the following sectors:
Governments
Defense
Transportation
Financial organizations across the following regions:
NATO member states
Ukraine
Commonwealth of Independent States (CIS) countries
Africa
Unique to this campaign, the group leveraged zero-click phishing emails that exploit a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform (CVE-2025-66376).
organisation
Commonwealth of Independent States
The attackers behind this campaign targeted Zimbra webmail in organizations in the following sectors:
Governments
Defense
Transportation
Financial organizations across the following regions:
NATO member states
Ukraine
Commonwealth of Independent States (CIS) countries
Africa
Unique to this campaign, the group leveraged zero-click phishing emails that exploit a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform (CVE-2025-66376).
organisation
the Zimbra Collaboration Suite
The attackers behind this campaign targeted Zimbra webmail in organizations in the following sectors:
Governments
Defense
Transportation
Financial organizations across the following regions:
NATO member states
Ukraine
Commonwealth of Independent States (CIS) countries
Africa
Unique to this campaign, the group leveraged zero-click phishing emails that exploit a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform (CVE-2025-66376).
organisation
ZCS
The attackers behind this campaign targeted Zimbra webmail in organizations in the following sectors:
Governments
Defense
Transportation
Financial organizations across the following regions:
NATO member states
Ukraine
Commonwealth of Independent States (CIS) countries
Africa
Unique to this campaign, the group leveraged zero-click phishing emails that exploit a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform (CVE-2025-66376).
organisation
HTML
Initial access starts with a phishing email that contains either an HTML attachment or embedded HTML in the message text.
organisation
CVE-2025-66376
Threat actors continue to actively target unpatched ZCS instances using CVE-2025-66376.
organisation
Scalable Vector Graphics
The obfuscated section creates an invisible Scalable Vector Graphics (SVG) element that, upon loading, decodes the Base64-encoded script into a JavaScript payload that it injects into the victim’s browser.
organisation
SVG
The obfuscated section creates an invisible Scalable Vector Graphics (SVG) element that, upon loading, decodes the Base64-encoded script into a JavaScript payload that it injects into the victim’s browser.
organisation
IP
Since we began tracking this campaign, there have been at least nine IP addresses and nine domains for the C2 servers.
organisation
the Indicators of Compromise (
See the Indicators of Compromise (IoC) section for a list of the IP addresses and domains used in CL-STA-1114 activity.
organisation
Palo Alto Networks
+82.080.467.8774
Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members.
organisation
Cyber Threat Alliance
+82.080.467.8774
Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members.
organisation
CTA
+82.080.467.8774
Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members.
organisation
zimbrastat[.]com
Indicators of Compromise
IP addresses
37.120.247[.]228
64.226.124[.]190
104.248.134[.]194
185.86.79[.]95
193.238.152[.]66
194.156.103[.]193
216.252.238[.]18
216.252.238[.]64
216.252.238[.]104
Domains
analyticemailmeter[.]com
emailanalytics[.]com[.]ua
istc-cloud[.]com
mailnalysis[.]com
synacorzimbra[.]nl
zimbra-metadata[.]com
zimbrastat[.]com
zimbrasoft[.]com[.]ua
zmailanalytics[.]com
Additional Resources
organisation
zmailanalytics[.]com
Indicators of Compromise
IP addresses
37.120.247[.]228
64.226.124[.]190
104.248.134[.]194
185.86.79[.]95
193.238.152[.]66
194.156.103[.]193
216.252.238[.]18
216.252.238[.]64
216.252.238[.]104
Domains
analyticemailmeter[.]com
emailanalytics[.]com[.]ua
istc-cloud[.]com
mailnalysis[.]com
synacorzimbra[.]nl
zimbra-metadata[.]com
zimbrastat[.]com
zimbrasoft[.]com[.]ua
zmailanalytics[.]com
Additional Resources
organisation
Additional Resources
Indicators of Compromise
IP addresses
37.120.247[.]228
64.226.124[.]190
104.248.134[.]194
185.86.79[.]95
193.238.152[.]66
194.156.103[.]193
216.252.238[.]18
216.252.238[.]64
216.252.238[.]104
Domains
analyticemailmeter[.]com
emailanalytics[.]com[.]ua
istc-cloud[.]com
mailnalysis[.]com
synacorzimbra[.]nl
zimbra-metadata[.]com
zimbrastat[.]com
zimbrasoft[.]com[.]ua
zmailanalytics[.]com
Additional Resources
Tactical Metrics
Metrics
infrastructure
Linux
Affected Product
Click for context!
A Russian state-sponsored threat group has been stealing sensitive data from governments and commercial organizations since July 2025 via a novel exploit in popular Linux-based enterprise software, U.S. authorities and cyber officials from more than a dozen other countries warned in a
joint cybersecurity advisory
Thursday.
Metrics
infrastructure
6.1
Software Version
The defect’s medium-severity rating of 6.1 underscores the challenge defenders regularly confront in prioritizing patching schedules based on measure of severity alone.
Intelligence Sources
CyberScoop
2026-07-23
Palo Alto
2026-07-23
Russian Global Webmail Espionage
Palo Alto
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-24T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
21x
target region
Target Country
Russian Federation
country
21x
organisation
Identified Entity
NATO
entity
8x
industry
Targeted Sector
Government
sector
5x
timeline
Temporal Reference
July 2025
date
5x
target region
Target Region
AFRICA
region
4x
tactic
Cyber Operation Type
Espionage
tactic
2x
tactic
MITRE ATT&CK Technique
T1059.007 - JavaScript
technique
2x
general metric
+1
866
+1
Contextual Telemetry
Context Block
6 METRICS
source region
Origin Country
Russian Federation
country
infrastructure
Affected Product
Linux
software
vulnerability
Exploited CVE
CVE-2025-66376
cve
infrastructure
Software Version
6.1
version
general metric
Incident
42
incident
general metric
South Korea
50
south korea
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.