The National Cyber and Information Security Agency of the Czech Republic (NÚKIB) has joined partners from several countries in issuing a Joint Cybersecurity Advisory concerning an ongoing cyber campaign by the threat group LAUNDRY BEAR, which has been targeting users of the Zimbra Collaboration Suite (ZCS) email platform since at least July 2025.
According to the advisory, actors linked to the Russian Federation are primarily seeking access to e-mail communications and other sensitive information from government institutions, the defence sector, energy organisations, media outlets, educational institutions, non-governmental organisations, and technology companies. The campaign exploits a vulnerability in the Zimbra webmail interface that allows malicious code to be executed simply by viewing a specially crafted e-mail in a vulnerable version of the system.
After successfully exploiting the vulnerability, attackers attempt to obtain e-mail contents, contact lists, authentication credentials, multi-factor authentication back-up codes, and other data that may subsequently be used for espionage activities. The campaign also includes efforts to maintain long-term access to compromised accounts.
NÚKIB recommends that organisations using Zimbra Collaboration Suite immediately verify that they are running updated versions of the platform containing the fix for vulnerability CVE‑2025‑66376. Organisations should also review available indicators of compromise, monitor suspicious activity related to email services, and pay increased attention to protecting user accounts.
The full advisory is available here: NSA and Partners Alert Zimbra Collaboration Suite Users of a Russian State-Supported Phishing Campaign > National Security Agency/Central Security Service > Press Release View

