EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Ransomware

Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite

Official source
EudorIA operational summary

What it means

Priority 95/100

CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.

Why it matters

L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.

Potential operational benefits

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
AudienceITSOCCISOManagement
Information centre

Translation in progress

CISA

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Cybersecurity Advisory Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Release Date July 23, 2026 Alert Code AA26-204A Related topics: Cyber Threats and Response Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Executive summary A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see Cybersecurity industry tracking ), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) [ 1 ]. LAUNDRY BEAR’s targeting is almost certainly to gather sensitive information for the Russian Federation, with these actors primarily focusing on the covert acquisition of email data. Previous campaigns indicated LAUNDRY BEAR relied on unsophisticated initial access techniques—including password spraying, phishing, and pass-the-cookie—allowing the group to successfully run high-volume operations. The latest campaign targeting ZCS uses a novel exploit that was a zero-day vulnerability when first exploited and continues to be successfully exploited. The vulnerability, Common Vulnerabilities and Exposures (CVE) CVE-2025-66376 , was patched in November 2025. This demonstrates LAUNDRY BEAR’s intent and ability to deploy increasingly sophisticated technical capabilities. Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicki

Indicatori CISA verificabili

27 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Ultima verifica: 2026-09-26T13:01:00.788534+00:00

Scarica STIX 2.1
TipoIndicatore (non cliccabile)File
domain-namei[.]emailanalytics[.]com[.]ua
domain-namei[.]analyticemailmeter[.]com
domain-namei[.]zimbra-metadata[.]com
domain-namei[.]zmailanalytics[.]com
ipv4-addr194[.]156[.]103[.]193
ipv4-addr216[.]252[.]238[.]64
ipv4-addr193[.]238[.]152[.]66
ipv4-addr64[.]226[.]124[.]190
ipv4-addr104[.]248[.]134[.]194
ipv4-addr185[.]86[.]79[.]95
ipv4-addr37[.]120[.]247[.]228
domain-namei[.]zimbrasoft[.]com[.]ua
domain-namei[.]istc-cloud[.]com
domain-nameistc-cloud[.]com
domain-namei[.]synacorzimbra[.]nl
domain-namesynacorzimbra[.]nl
domain-namezimbrasoft[.]com[.]ua
domain-namei[.]zimbrastat[.]com
domain-namezimbrastat[.]com
ipv4-addr216[.]252[.]238[.]18
domain-nameanalyticemailmeter[.]com
ipv4-addr216[.]252[.]238[.]104
domain-namei[.]mailnalysis[.]com
domain-namemailnalysis[.]com
domain-namezimbra-metadata[.]com
domain-nameemailanalytics[.]com[.]ua
domain-namezmailanalytics[.]com

Provenance

Allegato ufficiale CISA · 2026-07-22T18:44:20Z

SHA-512: 71d64755895c803274e1f093605dc653f622ad96f8353a1f21ad783ac41a7f883681030d82b60f37c6eb6a94b689bcb0341685aeebc47e68f62b702d116f9f86

Source
CISA Cybersecurity Advisories
Publishing entity
CISA
Entity type
National authority
Area
North America · US
Original language
en · translation in preparation
Publication
23/07/2026 14:00
Sharing
TLP:CLEAR
MITRE ATT&CK
T1027.010, T1027.013, T1027.017, T1048, T1048.002, T1048.003, T1074.002, T1078, T1087, T1098, T1114, T1114.002, T1119, T1185, T1199, T1203, T1550.004, T1556.006, T1557, T1560, T1566, T1583, T1583.003, T1587, T1587.001, T1587.004, T1588.002, T1588.007, T1589.001, T1589.002, T1593, T1595, T1596.005, T1597, T1597.002, T1608
CVE
CVE-2025-66376
Classification
Critical
Stated country
US
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Action indicated by the source

Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.

Official technical references

Open the original source