Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite

Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Russian state-supported actors tracked as LAUNDRY BEAR have been exploiting CVE-2025-66376 in Zimbra Collaboration Suite to steal email data and sensitive account information from Western organizations. The campaign uses a view-based phishing exploit, custom tooling called Ulej, and Flowerbed/Catcher infrastructure to collect and exfiltrate data via DNS and HTTPS. #LAUNDRYBEAR #ZimbraCollaborationSuite #CVE202566376 #Ulej #Flowerbed #Catcher

Keypoints

  • LAUNDRY BEAR, a Russian state-supported APT, has targeted Western government and commercial organizations since at least July 2025.
  • The group exploited CVE-2025-66376 in Zimbra Collaboration Suite using a malicious email that executes JavaScript when merely viewed.
  • The campaign focused on stealing the last 90 days of email content, Global Address List data, passwords, 2FA scratch codes, and application passcodes.
  • LAUNDRY BEAR used custom tooling named Ulej and infrastructure tied to Flowerbed and Catcher to aggregate and move stolen data.
  • Exfiltration occurred through both DNS and HTTPS, with payloads encoded, encrypted, and staged to evade basic detection.
  • Indicators of compromise include suspicious domains, VPS infrastructure, malicious email hashes, and artifacts such as ZCS localStorage entries and SOAP request activity.
  • Mitigations include patching ZCS, using alternative mail clients if needed, monitoring SOAP and DNS activity, and revoking exposed passcodes and credentials.

MITRE Techniques

  • [T1114.002] Remote Email Collection – The group abused legitimate APIs to bulk exfiltrate cloud email data (‘abusing legitimate APIs to perform data exfiltration in bulk’).
  • [T1078] Valid Accounts – The actors used stolen credentials from criminal marketplaces and compromised accounts to access victim mail (‘procuring stolen credentials on criminal marketplaces’).
  • [T1557] Adversary-in-the-Middle – Evilginx intercepted credentials and session tokens from a fake sign-in site (‘intercepted the user’s credentials’).
  • [T1587.001] Develop Capabilities: Malware – LAUNDRY BEAR used a custom-developed capability named Ulej (‘a custom-developed capability named “Улей” or “Ulej”’).
  • [T1114] Email Collection – The campaign targeted ZCS to steal email communications (‘successfully targeted and exfiltrated sensitive user information’).
  • [T1589.001] Gather Victim Identity Information: Credentials – The script attempted to collect the victim’s password (‘Password’).
  • [T1087] Account Discovery – The payload searched for the victim’s email address and gathered the GAL (‘attempts to discover the victim’s email address’).
  • [T1098] Account Manipulation – The script created a new application passcode to support persistent access (‘Newly-created Application Passcode’).
  • [T1595] Active Scanning – LAUNDRY BEAR likely found Zimbra targets via port scanning (‘by port scanning’).
  • [T1596.005] Search Open Technical Databases: Scan Databases – The group used commercial fingerprinting datasets to identify targets (‘fingerprinting datasets easily procured’).
  • [T1597.002] Search Closed Sources: Purchase Technical Data – The actors compiled user email addresses from commercial datasets (‘datasets offered by commercial vendors’).
  • [T1593] Search Open Websites/Domains – Open source intelligence helped build target lists (‘open source intelligence’).
  • [T1583.003] Acquire Infrastructure: Virtual Private Server – The actors procured VPSs for staging and exfiltration (‘procure VPSs from a variety of providers’).
  • [T1583] Acquire Infrastructure – Mullvad VPN was used to mask infrastructure interactions (‘primarily uses Mullvad VPN’).
  • [T1608] Stage Capabilities – Docker containers for Flowerbed were deployed onto new servers (‘deploy the Docker containers necessary’).
  • [T1048] Exfiltration Over Alternative Protocol – Catcher received victim data over DNS and HTTP (‘acts as both a DNS and HTTP server’).
  • [T1048.002] Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol – HTTPS was used as an encrypted exfiltration channel (‘disguise some of its exfiltration activity through an encrypted communications channel’).
  • [T1588.007] Obtain Capabilities: Artificial Intelligence – The Flowerbed codebase shows signs AI helped with development (‘artificial intelligence (AI) played a role’).
  • [T1588.002] Obtain Capabilities: Tool – The group relied on Evilginx2 as an open source tool (‘open source capabilities, such as Evilginx2’).
  • [T1566] Phishing – The initial access vector was a malicious email payload (‘sends an email containing a malicious JavaScript payload’).
  • [T1203] Exploitation for Client Execution – Viewing the malicious email executed JavaScript in the client (‘immediately executed once the user views’).
  • [T1587.004] Develop Capabilities: Exploits – The campaign used a zero-day exploit at the time (‘initially exploited a zero-day vulnerability’).
  • [T1027.017] Obfuscated Files or Information: SVG Smuggling – The payload was hidden in an SVG onload attribute (‘within the “onload” field of a Scalable Vector Graphics element’).
  • [T1027.013] Obfuscated Files or Information: Encrypted/Encoded File – The inner payload was Base64-encoded and XOR-encrypted (‘Base64 inner payload’).
  • [T1027.010] Obfuscated Files or Information: Command Obfuscation – The payload used extra non-functional @import directives to bypass detection (‘adding additional @import directives with non-functional code’).
  • [T1119] Automated Collection – The payload collected and exfiltrated information in stages (’12 asynchronous stages’).
  • [T1550.004] Use Alternate Authentication Material: Web Session Cookie – Prior campaigns bypassed MFA using session token replay (‘circumvent multi-factor authentication through session token replay’).
  • [T1185] Computer Account Discovery – The script used SOAP to determine the victim’s email address (‘GetIdentitiesRequest … to determine the victim’s email address’).
  • [T1556.006] Modify Authentication Process: Multi-Factor Authentication – The script created Application Passcodes to bypass 2FA (‘CreateAppSpecificPasswordRequest’).
  • [T1074.002] Data Staged: Remote Data Staging – Exfiltrated data was first stored on actor-controlled VPS infrastructure (‘stores the data in an actor-controlled … VPS’).
  • [T1048.003] Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol – Smaller payloads were exfiltrated through DNS queries (‘DNS A record queries’).
  • [T1560] Archive Collected Data – Emails were exfiltrated as a GZIP compressed archive (‘sent it as a GZIP compressed archive’).
  • [T1114.003] Email Collection: Remote Email Collection – Emails were pulled from the mail server via requests rather than from local storage (‘collected via API calls to the ZCS mail server’).
  • [T1090.002] Proxy: External Proxy – Mullvad VPN functioned as proxy-like infrastructure to obscure origin (‘to mask their identity’).

Indicators of Compromise

  • [Domains ] Flowerbed/Catcher infrastructure domains used for exfiltration and staging – zmailanalytics[.]com, zimbra-metadata[.]com, and 7 more domains
  • [IP addresses ] Associated with Flowerbed server infrastructure – 216.252.238[.]104, 216.252.238[.]18, and 7 more IPs
  • [SHA-1 hashes ] Let’s Encrypt certificate hashes tied to Flowerbed infrastructure – 2e4f314bc9943cab5005d6fde0b271c74d47bc9d, 50a87d926621dd06389ba50d86e0ff574ed713a8, and 8 more hashes
  • [Email addresses ] Addresses used to procure resources for the campaign – ivanka.zurabishvili@proton[.]me, zmul1@buildandconsulting[.]com, and 2 more addresses
  • [Email addresses ] Addresses used to distribute malicious payloads – c.laurent.ejfa@proton[.]me, j.moreau.epsc@proton[.]me, and 3 more addresses
  • [SHA-256 hashes ] Malicious email samples containing the payload – 98df604ecc57f884a2e6ce3266a0013ad64455cac48442c2312cfa4765007aaf, 60db9abae75cd8ccc49dd7ea5feb41677566dcd442f12ebc5745ffd2810fb874, and 2 more hashes
  • [File paths ] ZCS logs and local artifacts useful for detection – /opt/zimbra/log/mailbox.log, window.top.localStorage
  • [File names ] Exfiltration and telemetry artifacts written by Catcher – zimbra_batch_analytics.json, telemetryData_{0-89}.json
  • [HTTP path / content ] Exfiltration endpoint and content patterns – /v/p, pixel.gif
  • [Certificate names ] HTTPS wildcard certificates used by Flowerbed – *.i.zmailanalytics[.]com, *.i.synacorzimbra[.]nl
  • [Network infrastructure ] Named tools/services used in the campaign – Mullvad VPN, Let’s Encrypt, Cloudflare


Read more: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a