Security News

Cybersecurity news aggregator

CRITICAL Attacks Unit 42

Russian Global Webmail Espionage

A Russian state-aligned threat actor (CL-STA-1114/Void Blizzard) is exploiting a zero-click vulnerability (CVE-2025-66376, CVSS 7.2 HIGH) in Zimbra Collaboration Suite to inject malicious JavaScript via phishing emails, leading to automatic data exfiltration. The vulnerability affects Zimbra versions 10.0.0 through 10.0.17 and 10.1.0 through 10.1.12. Affected organizations must upgrade to the patched versions 10.0.18 or 10.1.13.
Read Full Article →

Threat Research Center Threat Research Cybercrime Cybercrime Russian Global Webmail Espionage 3 min read Related Products Advanced DNS Security Advanced URL Filtering Cloud-Delivered Security Services Cortex Unit 42 Incident Response By: Unit 42 Published: July 23, 2026 Categories: Cybercrime Threat Research Tags: CL-STA-1114 JavaScript Javascript injection Nation-state Obfuscation Phishing Zimbra webmail Share Executive Summary Unit 42 has observed a persistent cyberespionage campaign we track as CL-STA-1114. This activity cluster overlaps with activity from a Russian threat actor tracked by other vendors as Void Blizzard and LAUNDRY BEAR. The attackers behind this campaign targeted Zimbra webmail in organizations in the following sectors: Governments Defense Transportation Financial organizations across the following regions: NATO member states Ukraine Commonwealth of Independent States (CIS) countries Africa Unique to this campaign, the group leveraged zero-click phishing emails that exploit a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform (CVE-2025-66376). The exploit automatically injects a malicious JavaScript payload without requiring recipient interaction. Once executed, the payload exfiltrates sensitive user data, including login credentials, email archives, and search histories. Threat actors continue to actively target unpatched ZCS instances using CVE-2025-66376. Palo Alto Networks customers are better protected from the threats discussed above through the following products: Cortex Advanced Email Security Advanced URL Filtering and Advanced DNS Security If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team . Related Unit 42 Topics Cyberespionage , Phishing , Data Exfiltration Technical Analysis The attackers behind CL-STA-1114 have been active since at least 2024 , and this campaign targeting Zimbra servers started in July 2025. Initial access starts with a phishing email that contains either an HTML attachment or embedded HTML in the message text. This lure is designed to catch recipients' attention with news headlines. Figure 1 shows an example of the lure used and a snippet of the underlying HTML code. Figure 1. Example lure and a snippet of its underlying HTML content. The HTML text contains an obfuscated division with a Base64-encoded script (highlighted in red in Figure 1). The obfuscated section creates an invisible Scalable Vector Graphics (SVG) element that, upon loading, decodes the Base64-encoded script into a JavaScript payload that it injects into the victim’s browser. When executed, this JavaScript exfiltrates the victim’s Zimbra webmail data to a hard-coded command and control (C2) server. Exfiltrated data includes: CSRF tokens Email address and password Two-factor authentication (2FA) scratch codes System and environment details The victim’s last 90 days of email and search history Over the course of this campaign, we observed minimal changes to the JavaScript payload. Figure 2 illustrates the attack chain. Figure 2. The attack chain. Since we began tracking this campaign, there have been at least nine IP addresses and nine domains for the C2 servers. These servers were active for an average of 35.4 days. See the Indicators of Compromise (IoC) section for a list of the IP addresses and domains used in CL-STA-1114 activity. Conclusion This campaign activity in CL-STA-1114 illustrates the persistent and evolving threat of state-sponsored cyberespionage. The attacker behind this activity targets widely used mail platforms like Zimbra, posing a risk to critical industries globally. This research highlights the need for vigilance, proactive patching and advanced threat detection to protect organizations. Network administrators, defenders and security researchers should patch vulnerable systems and use the IoCs below to investigate and strengthen defenses against CL-STA-1114 and similar activity. Palo Alto Networks customers are better protected from the threats discussed above through the following products: The Cortex Advanced Email Security module routes suspicious HTML attachments to Advanced WildFire for static and dynamic analysis. This ensures that by the time an endpoint opens the attachment, it has already been scanned, allowing the agent to immediately act on a known verdict. Advanced URL Filtering and Advanced DNS Security identify known domains and URLs associated with this activity as malicious. If you think you may have been compromised or have an urgent matter, get in touch with the Unit 42 Incident Response team or call: North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42) UK: +44.20.3743.3660 Europe and Middle East: +31.20.299.3130 Asia: +65.6983.8730 Japan: +81.50.1790.0200 Australia: +61.2.4062.7950 India: 000 800 050 45107 South Korea: +82.080.467.8774 Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the Cyber Threat Alliance . Indicators of Compromise IP addresses 37.120.247[.]228 64.226.124[.]190 104.248.134[.]194 185.86.79[.]95 193.238.152[.]66 194.156.103[.]193 216.252.238[.]18 216.252.238[.]64 216.252.238[.]104 Domains analyticemailmeter[.]com emailanalytics[.]com[.]ua istc-cloud[.]com mailnalysis[.]com synacorzimbra[.]nl zimbra-metadata[.]com zimbrastat[.]com zimbrasoft[.]com[.]ua zmailanalytics[.]com Additional Resources Operation GhostMail: Russian APT exploits Zimbra Webmail to Target Ukraine State Agency – Seqrite Blog AIVD and MIVD identify new Russian cyber threat actor – AIVD/MIVD New Russia-affiliated actor Void Blizzard targets critical sectors for espionage – Microsoft Back to top Tags CL-STA-1114 JavaScript Javascript injection Nation-state Obfuscation Phishing Zimbra webmail Threat Research Center Next: Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy Table of Contents Related Articles The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector When “Hi, This Is IT” Comes Through Microsoft Teams Related Cybercrime Resources Insights May 28, 2026 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface Fiddling Scorpius Fighting Ursa Muddled Libra Read now Insights May 27, 2026 Out of the Crypt: The Evolving Cyber Extortion Economy Bling Libra Extortion Frontier AI Read now Threat Research March 16, 2026 Boggy Serpens Threat Assessment Advanced Persistent Threat Boggy Serpens C2 Read now Threat Actor Groups February 10, 2026 A Peek Into Muddled Libra’s Operational Playbook Muddled Libra PowerShell Scattered Spider Read now Insights February 3, 2026 Why Smart People Fall For Phishing Attacks AI Phishing Read now Insights January 29, 2026 Understanding the Russian Cyberthreat to the 2026 Winter Olympics AI IoT Russia Read now Threat Research December 10, 2025 01flip: Multi-Platform Ransomware Written in Rust Bitcoin CL-CRI-103 Cryptocurrency Read now Threat Research November 25, 2025 The Dual-Use Dilemma of AI: Malicious LLMs Credential Harvesting Data exfiltration LLM Read now Threat Research November 14, 2025 Digital Doppelgangers: Anatomy of Evolving Impersonation Campaigns Distributing Gh0st RAT DLL Sideloading Gh0st Rat PDNS Read now

Share this article