Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
2026-08-04T19:23:46Z•746af66036b04f1bf327ab86b12d1332a6a1a04a1e317215c5cae01f1de84f5b
CVE-2025-66376APTCISAChinaHMIICSIranOTPLCRussiaSCADAZimbracredential-accesscritical-infrastructurecybersecurity-advisoryespionagehacktivismincident-responseinternet-exposed-systemsnetwork-devicespersistencephishingroutersstate-sponsoredtelecommunications
What happened
CISA advisories report active state-sponsored and hacktivist cyber operations targeting collaboration platforms, networking infrastructure, telecommunications, critical infrastructure, operational technology, and government organizations. Key activity includes Russian actors exploiting Zimbra Collaboration Suite vulnerability CVE-2025-66376 for email theft, Russian FSB actors compromising poorly configured network devices, Chinese actors maintaining persistence in routers and using compromised infrastructure for espionage, Iranian-affiliated actors disrupting internet-exposed PLCs, and pro-R俄s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_alerts
- Record identifier
- 746af66036b04f1bf327ab86b12d1332a6a1a04a1e317215c5cae01f1de84f5b
- Enrichment time
- 2026-08-04T19:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.