CVE-2025-66376 Exploited in Russian Cyberespionage Campaign Targeting Zimbra Webmail

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Unit 42 has issued an advisory regarding a persistent cyberespionage campaign identified as CL-STA-1114, which targets Zimbra webmail systems. This campaign is attributed to a Russian threat actor known as Void Blizzard or LAUNDRY BEAR. The attackers exploit a vulnerability in the Zimbra Collaboration Suite (ZCS), specifically CVE-2025-66376, using zero-click phishing emails to exfiltrate sensitive user data without requiring any interaction from the recipient. Organizations in sectors such as government, defense, transportation, and finance across NATO member states, Ukraine, CIS countries, and Africa are particularly at risk. Immediate action is advised to patch vulnerable systems.

What the Advisory Covers

The advisory details the tactics, techniques, and procedures (TTPs) employed by the threat actors in this campaign. It highlights the use of zero-click phishing emails that exploit CVE-2025-66376, allowing attackers to inject malicious JavaScript payloads into the victim’s browser without any user interaction.

Affected Products and Versions

  • Zimbra Collaboration Suite (ZCS) – vulnerable versions are those that have not been patched against CVE-2025-66376.

Severity and Exploitation Status

The exploitation status of CVE-2025-66376 is active, with ongoing targeting of unpatched ZCS instances. The advisory does not specify a severity rating.

Available Patches or Fixed Versions

No specific patches or fixed versions are mentioned in the advisory. Organizations are urged to apply any available updates to ZCS to mitigate the risk.

Mitigations and Workarounds

No specific workarounds are provided. However, organizations should ensure that their ZCS installations are up to date and monitor for any suspicious activity.

Indicators of Compromise

IP Addresses

  • 37.120.247[.]228
  • 64.226.124[.]190
  • 104.248.134[.]194
  • 185.86.79[.]95
  • 193.238.152[.]66
  • 194.156.103[.]193
  • 216.252.238[.]18
  • 216.252.238[.]64
  • 216.252.238[.]104

Domains

  • analyticemailmeter[.]com
  • emailanalytics[.]com[.]ua
  • istc-cloud[.]com
  • mailnalysis[.]com
  • synacorzimbra[.]nl
  • zimbra-metadata[.]com
  • zimbrastat[.]com
  • zimbrasoft[.]com[.]ua
  • zmailanalytics[.]com

For further details, refer to the Unit 42 advisory.

Organizations are encouraged to remain vigilant and proactive in their cybersecurity measures to defend against such threats.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Berlin Investigates New Data Breach as Hackers Publish Stolen Login Credentials from Government Network

German authorities are currently investigating a new data breach involving Berlin’s government network, following the publication of stolen login credentials and other sensitive information...

ManageEngine to Highlight AI-Driven Cybersecurity Solutions at GISEC Global 2026 in Dubai

ManageEngine, a division of Zoho Corporation, is set to showcase its advanced cybersecurity solutions at GISEC Global 2026, scheduled for September 16-18 at the...

Toy Ghouls Unveils New Backdoors Utilizing HiveMQ and Element for C2 Communication

Introduction The cybersecurity landscape continues to evolve, with threat actors constantly adapting their tactics. One such group, known as Toy Ghouls (also referred to as...

North Korea commissions second Choe Hyon-class guided-missile destroyer

On Sunday, September 6, 2026, the North Korean Navy commissioned its second 5,000-ton Choe Hyon-class guided-missile destroyer, Kang Kon, in the eastern port city...