Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Alert! ASD, National Cyber Security Coordinator warn of ongoing Russian phishing campaign

The Australian Signals Directorate and Australia’s National Cyber Security Coordinator, Lieutenant General Michelle McGuinness, have warned of an ongoing phishing campaign being undertaken by Russian state-sponsored actors.

user icon Robert Dougherty Fri, 24 Jul 2026
Alert! ASD, National Cyber Security Coordinator warn of ongoing Russian phishing campaign

The joint advisory with international partners relates to cyber activity linked to the Russian state-sponsored group Laundry Bear.

It’s alleged that Russian state-sponsored cyber actors have been conducting phishing campaigns targeting users of Zimbra Collaboration Suite (ZCS) since July last year, with the intention to steal credentials and gain unauthorised access to email accounts and organisational networks.

The Russian state-supported advanced persistent threat group’s activity is tracked in the cyber security community under several names, primarily as “Laundry Bear”, a name initially coined by the Netherlands General Intelligence and Security Service and Defence Intelligence and Security Service.

 
 

“The advisory explains how the group exploited a previously unknown vulnerability in Zimbra Collaboration Suite to access organisations’ email systems,” said the Australian Signals Directorate.

“Unlike most phishing attacks, this technique can begin when a user simply views a malicious email in a vulnerable version of the webmail service.

“The group uses this technique to steal emails, contact lists and other sensitive information, and may attempt to maintain access to compromised networks for further malicious activity.

“Organisations using ZCS, particularly across government, law enforcement, technology, education, energy, media, NGOs, and the Defence Industrial Base, should review the advisory and assess whether they may be affected.

“We strongly encourage organisations and network defenders to apply security updates, patch vulnerable systems and monitor email services for signs of compromise. The advisory also includes guidance on identifying and responding to affected systems.”

Organisations are advised to enable multifactor authentication for all Zimbra accounts where possible, educate users to identify and report phishing emails and suspicious login requests, apply the latest security updates and patches for Zimbra Collaboration Suite, and monitor accounts and network activity for signs of unauthorised access or credential theft.

“Australia has joined Five Eyes and European partners to release a technical advisory warning of an ongoing phishing campaign being undertaken by Russian state-sponsored actors,” said the National Cyber Security Coordinator.

“The latest campaign highlighted by the Australian Signals Directorate has targeted organisations using the Zimbra Collaboration Suite online platform – likely for espionage purposes.

“Organisations using Zimbra Collaboration Suite should ensure they have implemented the recommended mitigations outlined in the advisory.

“Strong cyber hygiene matters. No country can be complacent about cyber threats, and Australia calls on all states and cyber actors to act responsibly in cyberspace.

“Australian entities can report cyber security incidents at cyber.gov.au or by calling the 24/7 Australian Cyber Security Hotline on 1300 CYBER1.”

Unlike traditional phishing campaigns that persuade a user to take an action, such as clicking a link or opening a file, Laundry Bear’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service.

Once viewed, the exploit attempts to exfiltrate the victim’s last 90 days of email communications, the organisation email directory (i.e., Global Address List [GAL]), and other sensitive information to servers controlled by Laundry Bear. The exploit also attempts to establish persistent access to victim accounts through a variety of means.

Laundry Bear has primarily relied on ProtonMail for distribution of the malicious email. However, more recent efforts have likely shifted to distributing the payload through previous victims.

This article was originally published on Cyber Daily’s sister brand, Defence Connect.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.