Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
2026-08-06T16:23:54Z•075aa0bcd20e24903f8fbe4a4a86e04c4f3c21ac1838eaff41f5c87387f55319
CVE-2025-66376CISAChina-nexusICSIranian-affiliated actorsLAUNDRY BEAROTPLCRussian cyber actorsSCADASalt TyphoonZimbra Collaboration Suitecovert proxy networkscritical infrastructureespionagehacktivismincident responsenetwork infrastructurephishingrouter compromisestate-sponsoredvulnerability managementzero-day exploitation
What happened
CISA advisories describe ongoing state-sponsored and aligned cyber activity targeting collaboration platforms, networking infrastructure, operational technology, and critical infrastructure. Russian actors exploit Zimbra Collaboration Suite CVE-2025-66376 for covert email collection and compromise vulnerable or poorly configured routers. China-nexus actors compromise network devices to build covert proxy infrastructure and enable espionage. Iranian-affiliated actors target internet-exposed PLCs and manipulate industrial control systems, while pro-Russia hacktivists conduct opportunistic OT/ICS
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_alerts
- Record identifier
- 075aa0bcd20e24903f8fbe4a4a86e04c4f3c21ac1838eaff41f5c87387f55319
- Enrichment time
- 2026-08-06T16:23:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.