Unit 42 tracked CL-STA-1114, a persistent cyberespionage campaign linked to the Russian threat actors Void Blizzard and LAUNDRY BEAR that targets Zimbra webmail in government, defense, transportation, and financial organizations across multiple regions. The attackers used zero-click phishing emails exploiting CVE-2025-66376 in Zimbra Collaboration Suite to inject JavaScript that steals credentials, 2FA scratch codes, session data, and email/search history from unpatched systems. #CL-STA-1114 #VoidBlizzard #LAUNDRYBEAR #Zimbra #CVE-2025-66376
Keypoints
- Unit 42 tracked the activity cluster as CL-STA-1114 and linked it to overlapping activity from Void Blizzard and LAUNDRY BEAR.
- The campaign has targeted Zimbra webmail users in government, defense, transportation, and financial sectors.
- Observed victims are located across NATO member states, Ukraine, CIS countries, and Africa.
- The attack uses zero-click phishing emails that exploit CVE-2025-66376 in Zimbra Collaboration Suite.
- The phishing messages contain HTML attachments or embedded HTML with an obfuscated Base64-encoded script that loads a malicious JavaScript payload.
- The payload exfiltrates CSRF tokens, email credentials, 2FA scratch codes, system details, and the victim’s last 90 days of email and search history.
- At least nine IP addresses and nine domains have been used for command-and-control infrastructure, with servers active for an average of 35.4 days.
MITRE Techniques
- [T1566.002] Phishing: Spearphishing Link/Attachment – Initial access was gained through phishing emails that contained HTML attachments or embedded HTML designed to lure recipients with news headlines. (‘The initial access starts with a phishing email that contains either an HTML attachment or embedded HTML in the message text.’)
- [T1059.007] Command and Scripting Interpreter: JavaScript – The malicious code decoded from Base64 and executed as a JavaScript payload in the victim’s browser. (‘decodes the Base64-encoded script into a JavaScript payload that it injects into the victim’s browser’)
- [T1027] Obfuscated Files or Information – The HTML contained an obfuscated division with an encoded script to hide the malicious content. (‘The HTML text contains an obfuscated division with a Base64-encoded script’)
- [T1105] Ingress Tool Transfer – The payload was loaded and executed from the delivered HTML content, bringing malicious code into the browser environment. (‘upon loading, decodes the Base64-encoded script into a JavaScript payload’)
- [T1041] Exfiltration Over C2 Channel – Stolen Zimbra data was sent to a hard-coded command-and-control server. (‘exfiltrates the victim’s Zimbra webmail data to a hard-coded command and control (C2) server’)
- [T1190] Exploit Public-Facing Application – The attackers exploited a Zimbra Collaboration Suite vulnerability to inject malicious code without user interaction. (‘zero-click phishing emails that exploit a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform (CVE-2025-66376)’)
Indicators of Compromise
- [IP addresses] C2 infrastructure used by CL-STA-1114 – 37.120.247[.]228, 64.226.124[.]190, and other 7 items
- [Domains] C2 infrastructure used by CL-STA-1114 – analyticemailmeter[.]com, emailanalytics[.]com[.]ua, and other 7 items
- [File names / attachment type] Phishing delivery artifacts – HTML attachment, embedded HTML
- [Vulnerability / exploit reference] Targeted Zimbra flaw enabling zero-click code injection – CVE-2025-66376
- [Malicious payload] Encoded script embedded in the lure – Base64-encoded script, JavaScript payload
Read more: https://unit42.paloaltonetworks.com/russian-webmail-espionage/