CISA, NSA and Partners Release Joint Cybersecurity Advisory on Russian State-Supported Phishing Campaign Targeting Zimbra Collaboration Suite Users

Cybersecurity and Infrastructure Security Agency (CISA)

You are subscribed to Cybersecurity Advisories for Cybersecurity and Infrastructure Security Agency. This information has recently been updated and is now available.

07/23/2026 10:20 PM EST

Today, the Cybersecurity and Infrastructure Security Agency (CISA) and National Security Agency (NSA), along with U.S. government and international partners, released a Joint Cybersecurity Advisory, Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite detailing malicious activity by the Russian state-supported threat group primarily known as LAUNDRY BEAR.

Since July 2025, LAUNDRY BEAR has targeted Zimbra Collaboration Suite (ZCS) webmail users in various U.S. organizations across the Defense Industrial Base, federal and local government, education, energy, law enforcement, media, technology, and non-governmental organizations (NGOs). The group uses novel data exfiltration and aggregation capability called “Ulej” (Russian for Beehive) to exploit CVE-2025-66376. Unlike traditional phishing that tries to persuade users to take an action, LAUNDRY BEAR’s campaign leverages a view-based exploit that only requires users to view a malicious email within a vulnerable version of the ZCS webmail service. Once viewed, the exploit can exfiltrate email communications, directories, and other sensitive data.

Synacor released a patch for CVE 2025-66376 for both 10.1.13 and 10.0.18 versions of ZCS in November 2025 and the vulnerability was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog in March 2026. LAUNDRY BEAR’s approach is notable for its manual identification of target organizations and persistent access attempts, indicating a focused espionage effort. The actors have shifted tactics, now distributing malicious emails from previously compromised accounts to further evade detection.

If your organization uses ZCS:

  • Ensure your ZCS software is patched and fully updated.
  • If patching is not possible, avoid using the Classic ZCS webmail client and use alternative mail clients.
  • Monitor for unusual activity, such as high volumes of outbound data, suspicious queries, or connections from virtual private network (VPN) providers commonly used by threat actors.

Read the full advisory and implement the detection and mitigation recommendations to protect your organization’s email infrastructure.

Please share your thoughts with us through this anonymous survey. We appreciate your feedback.

This product is provided subject to this Notification and this Privacy & Use policy.