Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
2026-07-30T12:23:50Z•920a324d6af24d24308610046e753294fa9416bd024bb6005dfed9b373fe6a89
CVE-2025-66376APTChinaICSIranOTPLCsRussiaSCADAZimbra Collaboration Suitecredential-theftcritical-infrastructureespionagehacktivismincident-responsenetworking-devicesoperational-technologypass-the-cookiepassword-sprayingpatch-managementphishingroutersstate-sponsored-activityvulnerability-exploitationzero-day-exploitation
What happened
CISA advisories describe state-sponsored and hacktivist campaigns targeting collaboration platforms, networking infrastructure, global routers, critical infrastructure OT/ICS, and government organizations. Key activity includes Russian exploitation of Zimbra Collaboration Suite CVE-2025-66376, Russian FSB targeting of vulnerable networking devices, PRC-linked compromise and persistence on routers to support espionage, Iranian-affiliated manipulation of internet-exposed PLCs, and opportunistic pro-Russia attacks against OT and critical infrastructure. Defenders should prioritize patching known/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_alerts
- Record identifier
- 920a324d6af24d24308610046e753294fa9416bd024bb6005dfed9b373fe6a89
- Enrichment time
- 2026-07-30T12:23:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.