Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite

2026-08-04T19:23:46Z746af66036b04f1bf327ab86b12d1332a6a1a04a1e317215c5cae01f1de84f5b
CVE-2025-66376APTCISAChinaHMIICSIranOTPLCRussiaSCADAZimbracredential-accesscritical-infrastructurecybersecurity-advisoryespionagehacktivismincident-responseinternet-exposed-systemsnetwork-devicespersistencephishingroutersstate-sponsoredtelecommunications

What happened

CISA advisories report active state-sponsored and hacktivist cyber operations targeting collaboration platforms, networking infrastructure, telecommunications, critical infrastructure, operational technology, and government organizations. Key activity includes Russian actors exploiting Zimbra Collaboration Suite vulnerability CVE-2025-66376 for email theft, Russian FSB actors compromising poorly configured network devices, Chinese actors maintaining persistence in routers and using compromised infrastructure for espionage, Iranian-affiliated actors disrupting internet-exposed PLCs, and pro-R俄s

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_alerts
Record identifier
746af66036b04f1bf327ab86b12d1332a6a1a04a1e317215c5cae01f1de84f5b
Enrichment time
2026-08-04T19:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite · Baitaphish