Russian Global Webmail Espionage
A persistent cyberespionage campaign, tracked as CL-STA-1114, originating from Russian threat actors (Void Blizzard and LAUNDRY BEAR) is targeting Zimbra webmail instances across various sectors, including governments, defense, and financial organizations. The attackers leverage zero-click phishing emails exploiting a vulnerability (CVE-2025-66376) to inject malicious JavaScript payloads that exfiltrate sensitive user data, including credentials, email history, and 2FA scratch codes. The campaign has been active since 2024 and involves a complex attack chain utilizing obfuscated Base64-encoded scripts and a network of command and control servers. Palo Alto Networks recommends proactive patching and advanced threat detection to mitigate these risks.
A persistent cyberespionage campaign, tracked as CL-STA-1114, is being conducted by Russian threat actors, including Void Blizzard and LAUNDRY BEAR. The campaign specifically targets Zimbra webmail instances within governments, defense organizations, and financial institutions globally. The attackers are exploiting a zero-click vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite (ZCS) to deliver malicious attacks. Initial access is gained through phishing emails containing either HTML attachments or embedded HTML code designed to trick recipients into opening them.
Upon successful execution, a JavaScript payload is injected into the victim’s browser, exfiltrating sensitive data. This data includes CSRF tokens, email addresses and passwords, two-factor authentication (2FA) scratch codes, system details, and the last 90 days of email and search history. The attackers use a complex attack chain involving obfuscated Base64-encoded scripts and a network of nine command and control (C2) servers, operating for an average of 35.4 days. These C2 servers are located at addresses including 37.120.247[.]228, 64.226.124[.]190, and others.
The campaign has been ongoing since at least 2024, with initial access occurring in July 2025. Palo Alto Networks recommends utilizing Cortex Advanced Email Security to route suspicious HTML attachments to Advanced WildFire for static and dynamic analysis, and leveraging Advanced URL Filtering and Advanced DNS Security to identify known domains and URLs associated with the campaign. Organizations should proactively patch vulnerable Zimbra instances and utilize the provided Indicators of Compromise (IoCs) to investigate and strengthen defenses. The Cyber Threat Alliance is sharing this intelligence with its members to rapidly deploy protections and disrupt malicious actors. Contact Palo Alto Networks Incident Response for assistance.
