Summary
Today we released a joint advisory with international partners about cyber activity linked to the Russian state-sponsored group known as LAUNDRY BEAR. The advisory explains how the group used a previously unknown flaw in Zimbra Collaboration Suite (ZCS) to access organisations' email systems. Unlike most phishing attacks, this technique does not require a user to click a link or open a file. The attack can begin when a user simply views a malicious email in a vulnerable version of the webmail service. The group uses this technique to steal emails, contact lists and other sensitive information. They may also try to stay inside a compromised network so they can carry out more attacks.