Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite

Russian state-supported cyber actors have been targeting users of Zimbra Collaboration Suite since at least July 2025. They are using phishing campaigns to compromise Western government and commercial organizations. The group is tracked as 'LAUNDRY BEAR'.
Reported by 1 outlet — CISA. See all sources ↓
Russian state-supported cyber actors are targeting users of Zimbra Collaboration Suite. They are using phishing campaigns to compromise Western government and commercial organizations. This has been happening since at least July 2025.
Why it matters
This is important because it shows that Russian state-supported cyber actors are still active and targeting Western organizations. It also highlights the need for better cybersecurity measures.
- Who is behind the phishing campaigns?
- Russian state-supported cyber actors
- What software are they targeting?
- Zimbra Collaboration Suite
- When did this start?
- At least July 2025
How outlets are framing the same story
These are the main editorial angles found across reporting. Use them to quickly compare what different outlets emphasize, omit, or question.
The outlets report the same facts but do not provide additional context or analysis.
- Coverage cardFraming signal1AngleScouting report
Russian state-supported cyber actors are a threat to Western organizations
Sources1TypeAngleCISAtracks the group as 'LAUNDRY BEAR'