Joint cyber security advisory on Russian state-sponsored phishing campaign targeting Zimbra webmail

The Canadian Centre for Cyber Security (Cyber Centre) has joined the United States National Security Agency (NSA) and other international partners in releasing a cyber security advisory warning of a Russian state-sponsored phishing campaign targeting users of Zimbra Collaboration Suite (ZCS).

The joint advisory warns that Russia-sponsored threat actors associated with an advanced persistent threat group, known as Laundry Bear, are exploiting a known vulnerability in Zimbra webmail. As a result, user accounts may be compromised and sensitive information may be accessed, including credentials, authentication data and email content.

The authoring agencies caution that this activity reflects ongoing efforts by state-sponsored actors to exploit known vulnerabilities, while leveraging increasingly sophisticated techniques to evade detection.

To mitigate the risks associated with this activity, organizations using ZCS should immediately apply security patches and updates to Zimbra systems and monitor for any unusual account activity.

Consult the full joint cyber security advisory: Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite (PDF)

Date modified: