Unit 42
Read post

Russian Global Webmail Espionage

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Unit 42 has identified a persistent Russian cyberespionage campaign (CL-STA-1114), overlapping with threat actors known as Void Blizzard and LAUNDRY BEAR, targeting Zimbra Collaboration Suite webmail servers. The campaign exploits CVE-2025-66376, a zero-click phishing vulnerability that automatically injects a malicious JavaScript payload via obfuscated HTML emails containing Base64-encoded SVG elements. Once executed, the payload exfiltrates CSRF tokens, credentials, 2FA scratch codes, and up to 90 days of email and search history to attacker-controlled C2 servers. Targets include government, defense, transportation, and financial organizations across NATO states, Ukraine, CIS countries, and Africa. At least nine C2 IP addresses and nine domains have been identified. Organizations are urged to patch unpatched ZCS instances immediately and use the provided IoCs to investigate exposure.

    #security#phishing
Jul 23•4m read time•From unit42.paloaltonetworks.com
Post cover image
Table of contents
Executive SummaryTechnical AnalysisConclusionIndicators of CompromiseAdditional Resources
35 Impressions
Unit 42's image
Unit 42

Unit42 is a cybersecurity research team known for its analysis of cyber threats, malware, and cyber...

63 Followers

•

72 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard