The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI) and other U.S. government and international partners have published a joint Cybersecurity Advisory, “Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite (ZCS).” Known primarily as LAUNDRY BEAR, the Russian advanced persistent threat (APT) group’s ongoing covert efforts appear focused on targeting Western government and commercial organizations to gather email data possibly for espionage. The advisory shares mitigations, indicators of compromise, and remediation to harden networks that use ZCS webmail against this ongoing threat activity.
Unlike traditional phishing that attempts to persuade a user to take an action, such as clicking a link or downloading a file, LAUNDRY BEAR’s current campaign uses a zero-click exploit that only requires a user to view a malicious email within a vulnerable version of the ZCS webmail service. This campaign uses a custom-developed aggregation and data exfiltration capability called Ulej to exploit a common vulnerabilities and exposures (CVE) in ZCS, CVE-2025-66376, with the potential for adaption to exploit other vulnerabilities as well. This advisory provides several mitigations to protect against this activity and specific remediation actions for organizations that detect indicators of compromise in their environment.
“CISA continues to see sophisticated and less sophisticated nation-state cyber groups deploy increasingly novel exploits into a highly successful capability to disrupt critical infrastructure or conduct espionage,” said Acting Executive Assistant Director for Cybersecurity Chris Butera. “With our partners, CISA encourages organizations to continually update all their ZCS mail service software and continuously monitor their mail services and emails for malicious activity.”
“Russian state-sponsored cyber actors have spent years quietly extracting configuration data from poorly configured routers across critical infrastructure,” said Assistant Director Brett Leatherman of the FBI’s Cyber Division. “This advisory gives network defenders the visibility to spot this activity and the mitigations to counter it. The FBI will work with our partners to continue to expose this tradecraft and hold these actors accountable.”
Since July 2025, more than 10 organizations that use the ZCS software were successfully targeted by LAUNDRY BEAR, which exfiltrated or attempted to exfiltrate sensitive user information including email address, password, and two factor authentication (2FA) tokens. Primary Western organizations targeted by this ZCS campaign using the Ulej capability include Defense Industrial Base (DIB), federal and local government, law enforcement, technology, education, media, and non-governmental organizations.
The original announcement can be found here.



