U.S. and international cybersecurity agencies warned that a Russian state-supported hacking group is conducting a stealthy phishing campaign against users of the Zimbra Collaboration Suite, exploiting a newly identified vulnerability to siphon email data for potential espionage.
In a joint advisory released today, the Cybersecurity and Infrastructure Security Agency, the National Security Agency, the Federal Bureau of Investigation and foreign partners said the group—known as LAUNDRY BEAR—has been targeting Western government and commercial entities. The alert outlines indicators of compromise, mitigations and remediation steps intended to help organizations harden Zimbra webmail deployments against the ongoing activity.
Unlike conventional phishing that relies on tricking recipients into clicking a link or opening an attachment, the campaign uses a zero-click technique that can trigger simply when a victim views a malicious message in vulnerable versions of Zimbra webmail, the agencies said. The actors are using a bespoke aggregation and exfiltration tool called Ulej to exploit CVE-2025-66376 and could adapt it to other flaws.
“CISA continues to see sophisticated and less sophisticated nation-state cyber groups deploy increasingly novel exploits into a highly successful capability to disrupt critical infrastructure or conduct espionage,” said Acting Executive Assistant Director for Cybersecurity Chris Butera. “With our partners, CISA encourages organizations to continually update all their ZCS mail service software and continuously monitor their mail services and emails for malicious activity.”
Since July 2025, more than 10 Zimbra-using organizations have been successfully targeted, with attackers exfiltrating or attempting to steal email addresses, passwords and two-factor authentication tokens, according to the advisory. Sectors singled out include the Defense Industrial Base, federal and local government, law enforcement, technology, education, media and non-governmental organizations.
“Russian state-sponsored cyber actors have spent years quietly extracting configuration data from poorly configured routers across critical infrastructure,” said Assistant Director Brett Leatherman of the FBI’s Cyber Division. “This advisory gives network defenders the visibility to spot this activity and the mitigations to counter it. The FBI will work with our partners to continue to expose this tradecraft and hold these actors accountable.”
The agencies urged organizations running Zimbra to apply updates promptly, monitor webmail services and email traffic for suspicious behavior, review the advisory’s mitigations, and take specific remediation steps if indicators of compromise are found.






