Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite

2026-08-06T16:23:54Z075aa0bcd20e24903f8fbe4a4a86e04c4f3c21ac1838eaff41f5c87387f55319
CVE-2025-66376CISAChina-nexusICSIranian-affiliated actorsLAUNDRY BEAROTPLCRussian cyber actorsSCADASalt TyphoonZimbra Collaboration Suitecovert proxy networkscritical infrastructureespionagehacktivismincident responsenetwork infrastructurephishingrouter compromisestate-sponsoredvulnerability managementzero-day exploitation

What happened

CISA advisories describe ongoing state-sponsored and aligned cyber activity targeting collaboration platforms, networking infrastructure, operational technology, and critical infrastructure. Russian actors exploit Zimbra Collaboration Suite CVE-2025-66376 for covert email collection and compromise vulnerable or poorly configured routers. China-nexus actors compromise network devices to build covert proxy infrastructure and enable espionage. Iranian-affiliated actors target internet-exposed PLCs and manipulate industrial control systems, while pro-Russia hacktivists conduct opportunistic OT/ICS

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_alerts
Record identifier
075aa0bcd20e24903f8fbe4a4a86e04c4f3c21ac1838eaff41f5c87387f55319
Enrichment time
2026-08-06T16:23:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.