Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite

2026-08-05T19:23:47Z84fab5632c92f638da5e9e8722842e7feda326f3c812090ef61fde8d87075eb2
CVE-2025-66376CISACVE exploitationChinaICSIranLAUNDRY BEAROTPLCRussiaSCADAZimbra Collaboration Suitecritical infrastructureespionageincident responsenetwork device compromisepass-the-cookiepassword sprayingpersistencephishingpro-Russia hacktivistsrouter securitystate-sponsoredtelecommunicationszero-day

What happened

CISA advisories report active state-sponsored and hacktivist cyber operations targeting Zimbra Collaboration Suite, exposed networking devices, compromised infrastructure, internet-facing PLCs and OT environments, and global telecommunications and government networks. Activity includes zero-day exploitation of CVE-2025-66376, phishing, password spraying, pass-the-cookie, router compromise and persistence, manipulation of PLC/SCADA systems, and opportunistic attacks against critical infrastructure. Advisories emphasize urgent patching, removing OT and network devices from direct internet access

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_alerts
Record identifier
84fab5632c92f638da5e9e8722842e7feda326f3c812090ef61fde8d87075eb2
Enrichment time
2026-08-05T19:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.