unit42 · Crawled Jul 23, 2026

Russian Global Webmail Espionage

18 IoCs 1 Actors 1 CVEs
Read original article ↗

AI Summary

Unit 42 has identified a persistent cyberespionage campaign, tracked as CL-STA-1114, attributed to a Russian threat actor. The campaign targets Zimbra webmail users in government, defense, transportation, and financial sectors across NATO, Ukraine, CIS, and African countries. Attackers exploit CVE-2025-66376 to deliver a zero-click JavaScript payload that exfiltrates credentials, email archives, and 2FA tokens. The activity highlights ongoing state-sponsored threats leveraging unpatched vulnerabilities in widely used collaboration platforms.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 18 extracted

Type Value Detail
IP 37[.]120[.]247[.]228 Details →
IP 64[.]226[.]124[.]190 Details →
IP 104[.]248[.]134[.]194 Details →
IP 185[.]86[.]79[.]95 Details →
IP 193[.]238[.]152[.]66 Details →
IP 194[.]156[.]103[.]193 Details →
IP 216[.]252[.]238[.]18 Details →
IP 216[.]252[.]238[.]64 Details →
IP 216[.]252[.]238[.]104 Details →
Domain analyticemailmeter[.]com Details →
Domain emailanalytics[.]com[.]ua Details →
Domain istc-cloud[.]com Details →
Domain mailnalysis[.]com Details →
Domain synacorzimbra[.]nl Details →
Domain zimbra-metadata[.]com Details →
Domain zimbrastat[.]com Details →
Domain zimbrasoft[.]com[.]ua Details →
Domain zmailanalytics[.]com Details →

MITRE ATT&CK TTPs 39 techniques

T1003 OS Credential Dumping · Credential Access T1003.001 LSASS Memory · Credential Access T1021.003 Distributed Component Object Model · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1055 Process Injection · Defense Evasion T1056.001 Keylogging · Collection T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1059.007 JavaScript · Execution T1070.004 File Deletion · Defense Evasion T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1071.003 Mail Protocols · Command And Control T1071.004 DNS · Command And Control T1074.001 Local Data Staging · Collection T1080 Taint Shared Content · Lateral Movement T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1090 Proxy · Command And Control T1098 Account Manipulation · Persistence T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1114 Email Collection · Collection T1132.002 Non-Standard Encoding · Command And Control T1190 Exploit Public-Facing Application · Initial Access T1203 Exploitation for Client Execution · Execution T1204.002 Malicious File · Execution T1485 Data Destruction · Impact T1496 Resource Hijacking · Impact T1530 Data from Cloud Storage · Collection T1539 Steal Web Session Cookie · Credential Access T1552 Unsecured Credentials · Credential Access T1555 Credentials from Password Stores · Credential Access T1557 Adversary-in-the-Middle · Credential Access T1558.003 Kerberoasting · Credential Access T1566 Phishing · Initial Access T1568 Dynamic Resolution · Command And Control T1570 Lateral Tool Transfer · Lateral Movement T1588 Obtain Capabilities · Resource Development