How the CL-STA-1114 attack works (CVE-2025-66376)
Unit 42 describes a zero-click phishing campaign that exploits a vulnerability in the Zimbra Collaboration Suite (CVE-2025-66376). Initial access begins with a phishing message that contains either an HTML attachment or embedded HTML in the email body. The lure is crafted to resemble attention-grabbing news headlines. The embedded HTML hides an obfuscated division containing a Base64-encoded script. That code creates an invisible Scalable Vector Graphics (SVG) element which, when loaded, decodes the Base64 payload into JavaScript and injects it into the recipient’s browser without requiring any further interaction.
Once executed, the malicious JavaScript exfiltrates Zimbra webmail data to a hard-coded command-and-control (C2) server. Unit 42 observed the payload consistently stealing CSRF tokens, email addresses and passwords, two-factor authentication (2FA) scratch codes, system and environment details, and the victim’s last 90 days of email and search history. Across the campaign, the JavaScript payload showed minimal change, indicating a stable, repeatable exploit chain.
Targets, sectors, and geography
Unit 42 tracked this activity cluster as CL-STA-1114 and noted overlap with a Russian threat actor other vendors call Void Blizzard and LAUNDRY BEAR. The attackers targeted Zimbra webmail instances across specific sectors: governments, defense, transportation, and financial organizations. Geographically the campaign hit NATO member states, Ukraine, Commonwealth of Independent States (CIS) countries, and destinations in Africa. The pattern shows a deliberate focus on organizations that rely on widely used mail platforms.
Infrastructure and indicators of compromise
Unit 42 reported at least nine IP addresses and nine domains used as C2 infrastructure for CL-STA-1114. These servers were active for an average of 35.4 days. The IP addresses observed include 37.120.247[.]228; 64.226.124[.]190; 104.248.134[.]194; 185.86.79[.]95; 193.238.152[.]66; 194.156.103[.]193; 216.252.238[.]18; 216.252.238[.]64; and 216.252.238[.]104.
- analyticemailmeter[.]com
- emailanalytics[.]com[.]ua
- istc-cloud[.]com
- mailnalysis[.]com
- synacorzimbra[.]nl
- zimbra-metadata[.]com
- zimbrastat[.]com
- zimbrasoft[.]com[.]ua
- zmailanalytics[.]com
Unit 42 recommends that network administrators and defenders use these Indicators of Compromise (IoCs) to investigate potential infections and strengthen defenses against CL-STA-1114 and similar activity.
Protections, vendor response, and how to get help
Palo Alto Networks listed product features that can mitigate the threat. The Cortex Advanced Email Security module routes suspicious HTML attachments to Advanced WildFire for static and dynamic analysis so attachments are scanned before an endpoint opens them. Advanced URL Filtering and Advanced DNS Security can identify domains and URLs associated with this activity as malicious. Palo Alto Networks also shared these findings with Cyber Threat Alliance (CTA) members; the CTA uses such intelligence to rapidly deploy protections to customers and to systematically disrupt malicious cyber actors.
If an organization believes it may have been compromised or requires urgent assistance, Unit 42 directed readers to contact its Incident Response team. Regional contact numbers provided in the advisory include North America toll free +1 (866) 486-4842 (866.4.UNIT42); UK +44.20.3743.3660; Europe and Middle East +31.20.299.3130; Asia +65.6983.8730; Japan +81.50.1790.0200; Australia +61.2.4062.7950; India 000 800 050 45107; and South Korea +82.080.467.8774.
What this means for defenders, CTA members, and affected organizations
Technologists and security teams: Patch vulnerable Zimbra Collaboration Suite instances and scan mail servers for the listed IoCs. Unit 42’s advisory specifically highlights proactive patching and advanced threat detection as necessary defenses against this zero-click technique.
Cyber Threat Alliance members: The advisory notes that CTA members use shared intelligence to rapidly deploy protections and to disrupt malicious actors — an operational pathway that CTA members can continue to leverage as new IoCs appear.
Affected organizations and procurement leaders in government, defense, transportation, and finance: Check Zimbra servers for signs of compromise, prioritize remediation of CVE-2025-66376, and reach out to incident responders if there is cause for concern. Unit 42 provided regional contact numbers for direct engagement.
CL-STA-1114 is a reminder that a single, weaponized webmail vulnerability can yield high-value access across sectors and continents. The exploitation technique — an invisible SVG element decoding Base64 into executable JavaScript — made the campaign both stealthy and effective. The concrete remedies Unit 42 points to are familiar: patching the CVE, applying IoCs, and using layered email and DNS defenses. How quickly organizations act on those specific steps will determine whether this cluster remains a contained nuisance or continues to be a persistent espionage threat.
https://unit42.paloaltonetworks.com/russian-webmail-espionage/




