Summary
Key Points:
- Ongoing phishing campaign by the Russian APT group LAUNDRY BEAR targeting users of the Zimbra Collaboration Suite (ZCS) using a zero-click exploit.
- Impact includes potential exfiltration of sensitive user information such as email addresses, passwords, and 2FA tokens from over 10 organizations, primarily in the Defense Industrial Base and government sectors.
- Recommended actions include updating ZCS software, monitoring for malicious activity, and implementing mitigations outlined in the advisory.
Technical Details: The campaign exploits CVE-2025-66376 in ZCS to facilitate data exfiltration via a custom tool named Ulej. This zero-click exploit allows attackers to compromise systems merely by having users view a malicious email.
MITRE ATT&CK Techniques:
- T1566 - Phishing (Initial Access)
- T1203 - Exploit Public-Facing Application (Initial Access)
- T1041 - Exfiltration Over Command and Control Channel (Exfiltration)
IOCs Mentioned:
- CVE-2025-66376
Join the discussion — sign up to comment, upvote, and save articles.