Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite

2026-07-30T12:23:50Z920a324d6af24d24308610046e753294fa9416bd024bb6005dfed9b373fe6a89
CVE-2025-66376APTChinaICSIranOTPLCsRussiaSCADAZimbra Collaboration Suitecredential-theftcritical-infrastructureespionagehacktivismincident-responsenetworking-devicesoperational-technologypass-the-cookiepassword-sprayingpatch-managementphishingroutersstate-sponsored-activityvulnerability-exploitationzero-day-exploitation

What happened

CISA advisories describe state-sponsored and hacktivist campaigns targeting collaboration platforms, networking infrastructure, global routers, critical infrastructure OT/ICS, and government organizations. Key activity includes Russian exploitation of Zimbra Collaboration Suite CVE-2025-66376, Russian FSB targeting of vulnerable networking devices, PRC-linked compromise and persistence on routers to support espionage, Iranian-affiliated manipulation of internet-exposed PLCs, and opportunistic pro-Russia attacks against OT and critical infrastructure. Defenders should prioritize patching known/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_alerts
Record identifier
920a324d6af24d24308610046e753294fa9416bd024bb6005dfed9b373fe6a89
Enrichment time
2026-07-30T12:23:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.