On July 23, the National Security Agency (NSA) in collaboration with partners, released a Cybersecurity Advisory (CSA) titled, “Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite.”
Since July 2025, the Russian state-supported advanced persistent threat group known as LAUNDRY BEAR has utilized phishing emails to target the Zimbra Collaboration Suite (ZCS) across various U.S. and allied government and commercial networks. Supported by a custom-developed capability named “Ulej,” the actors leverage a view-based exploit that triggers automatically when a user views a malicious email within a vulnerable version of the webmail service. This exploited a zero-day vulnerability (CVE-2025-66376) when it was first used by the threat group and is still used to successfully exploit ZCS instances that are still unpatched. The exploit attempts to exfiltrate the organization’s email directory, the last 90 days of the victim’s communications, and other sensitive information to servers controlled by the actors.
The joint CSA characterizes the network activity occurring during the exfiltration stage and documents observed indicators of comprise (IOCs) to help organizations develop robust detection and mitigation capabilities. The report also provides specific remediations steps for organizations that discover the presence of the listed IOCs.
Co-sealing agencies include the Federal Bureau of Investigation (FBI), Netherlands Defence Intelligence and Security Service (MIVD), Netherlands General Intelligence and Security Service (AIVD), Cybersecurity and Infrastructure Security Agency (CISA), Defense Counterintelligence and Security Agency (DCSA), Department of Defense Cyber Crime Center (DC3), Department of the Treasury, Naval Criminal Investigative Service (NCIS), Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre), New Zealand National Cyber Security Centre (NCSC-NZ), United Kingdom National Cyber Security Centre (NCSC-UK), Czech Republic National Cyber and Information Security Agency (NÚKIB), Danish Defence Intelligence Service (DDIS), Estonian Foreign Intelligence Service (EFIS), Finnish Defence Intelligence (FDI), Finnish Security and Intelligence Service (SUPO), French General Directorate for Internal Security (DGSI), French National Cybersecurity Agency (ANSSI), Italian External Intelligence and Security Agency (AISE), Italian Internal Intelligence and Security Agency (AISI), Security and Intelligence Service of the Republic of Moldova (SIS RM), Polish Foreign Intelligence Agency (AW), The Military Counterintelligence Service of Poland (SKW), Spain National Intelligence Centre (CNI), Sweden National Cyber Security Centre (NCSC-SE).
Source: NSA
IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.









