
CISA warns Russian-backed hackers are targeting Zimbra webmail users
CISA and NSA say Russian-backed LAUNDRY BEAR hackers are targeting Zimbra webmail users to collect email data.
U.S. and allied cyber agencies have issued a new warning that Russian state-supported operators are targeting users of Zimbra Collaboration Suite, the email and collaboration platform still used by governments, schools, energy organizations and commercial networks. The July 23 advisory, led by CISA and NSA with FBI and international partners, says the activity has been under way since at least July 2025 and is focused on covertly collecting email data.
The agencies connect the campaign to an advanced persistent threat group widely tracked as LAUNDRY BEAR. According to the advisory, earlier operations by the group relied on familiar initial-access methods such as password spraying, phishing and stolen session cookies. The latest warning is more urgent because it describes phishing messages built to exploit Zimbra webmail users, including cases where malicious content can run when a vulnerable message is viewed in an unpatched environment.
Why it matters
Email systems remain one of the most valuable targets in an espionage campaign. A mailbox can expose negotiations, credentials, internal contacts, calendar information and attachments that help attackers move deeper into an organization. CISA says the campaign has affected or targeted organizations tied to the defense industrial base, government, education, energy, law enforcement, media, technology and non-governmental sectors.
The advisory also details infrastructure and tooling used to disguise collection and exfiltration. It says the operators have used compromised accounts to send malicious mail and have routed some exfiltration through encrypted channels. That combination makes the activity harder to spot with simple awareness training or blocklists alone, especially where attackers can reuse legitimate services or accounts that have already been compromised.
What defenders should do
The practical guidance is straightforward: organizations running Zimbra should update mail service software, monitor ZCS logs and browser local storage for the indicators listed by the agencies, and review suspicious authentication and mail-access activity. The advisory includes STIX files and detailed indicators of compromise for security teams that want to sweep logs and detection platforms.
For organizations that do not run Zimbra, the broader lesson still applies. State-backed email collection campaigns continue to mix social engineering, credential abuse and software vulnerabilities. Mail servers and webmail clients need the same patch discipline, telemetry and incident response planning as internet-facing VPNs, identity systems and cloud administration tools.
Sources
Cover photo by cottonbro studio on Pexels, used under the Pexels License.
CyberOGZ Team






Comments (0)
Leave a Comment