DomainFork
Markets
MarketsCompaniesCryptoCommoditiesIslamic Finance
Money
Personal FinanceProperty
World
MalaysiaASEANAsiaWorld
Business
TechnologyStartupsOpinion
Intelligence
AI EdgeOSINT Desk
Media
VideoAudioLifestyle
Breaking
The Computer That Helped Win World War II7/23/2026Aneka Jaringan’s 9M26 PAT Plunges 91.6% To RM0.37 MillionAlpha IVF Declares 0.6 Sen Dividend Despite FY26 PATMI Falls 6.8% To RM53.6 Million7/22/2026Mendag Kunjungi UMKM Coklat nDalam dan Base Artisan di YogyakartaMendag Menjadi Pembicara Utama pada the 9th Indonesia International Cocoa Conference (IICC) 2026ກອງປະຊຸມປຶກສາຫາລື ກ່ຽວກັບ ບົດສະຫຼຸບຂໍ້ມູນສະຖິຕິ ສຳລັບ ການຈັດຕັ້ງປະຕິບັດແຜນພັດທະນາເສດຖະກິດ-ສັງຄົມແຫ່ງຊາດ ຄັ້ງທີ X ປະຈຳ 6 ເດືອນຕົ້ນປີ 2026 ແລະ ຄາດຄະເນ 6 ເດືອນທ້າຍປີ 2026The Year in ReviewAPI Latency Improvements and Revised SLOsTop cryptocurrencies lower; Bitcoin drops below $65,000 levelOil prices hit $100 for the first time since May - BBCFull CircleRickson Goh shows how you deal with a pandemicAMRO Cafe Seminar: Who Takes the Hit? The Uneven Impacts of Generative AI on Labor Demand Across CountriesDOF completes sale of Makati property for PhP1 Billion, boosts revenues for national developmentAMRO Cafe Seminar SeriesMural bertema edukasi di Kampung Mutihan Soloประกาศรายชื่อผู้ผ่านการสอบสัมภาษณ์ ตำแหน่งหมายเลข 101, 104, 105 และ 106AOT เดินหน้าต้านทุจริต เปิดเวทีสร้างค่านิยมสุจริต ตอกย้ำจุดยืนไม่เอาคอร์รัปชันทุกรูปแบบThe Computer That Helped Win World War II7/23/2026Aneka Jaringan’s 9M26 PAT Plunges 91.6% To RM0.37 MillionAlpha IVF Declares 0.6 Sen Dividend Despite FY26 PATMI Falls 6.8% To RM53.6 Million7/22/2026Mendag Kunjungi UMKM Coklat nDalam dan Base Artisan di YogyakartaMendag Menjadi Pembicara Utama pada the 9th Indonesia International Cocoa Conference (IICC) 2026ກອງປະຊຸມປຶກສາຫາລື ກ່ຽວກັບ ບົດສະຫຼຸບຂໍ້ມູນສະຖິຕິ ສຳລັບ ການຈັດຕັ້ງປະຕິບັດແຜນພັດທະນາເສດຖະກິດ-ສັງຄົມແຫ່ງຊາດ ຄັ້ງທີ X ປະຈຳ 6 ເດືອນຕົ້ນປີ 2026 ແລະ ຄາດຄະເນ 6 ເດືອນທ້າຍປີ 2026The Year in ReviewAPI Latency Improvements and Revised SLOsTop cryptocurrencies lower; Bitcoin drops below $65,000 levelOil prices hit $100 for the first time since May - BBCFull CircleRickson Goh shows how you deal with a pandemicAMRO Cafe Seminar: Who Takes the Hit? The Uneven Impacts of Generative AI on Labor Demand Across CountriesDOF completes sale of Makati property for PhP1 Billion, boosts revenues for national developmentAMRO Cafe Seminar SeriesMural bertema edukasi di Kampung Mutihan Soloประกาศรายชื่อผู้ผ่านการสอบสัมภาษณ์ ตำแหน่งหมายเลข 101, 104, 105 และ 106AOT เดินหน้าต้านทุจริต เปิดเวทีสร้างค่านิยมสุจริต ตอกย้ำจุดยืนไม่เอาคอร์รัปชันทุกรูปแบบ
Home/OSINT
Economy

Russian Global Webmail Espionage

Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global Webmail Espionage appeared first on Unit 42 .

Source: Palo Alto Unit 42 · July 23, 2026 at 10:55 PM · AI-assisted report

Russian Global Webmail Espionage
DomainFork
Image: unit42.paloaltonetworks.com

KUALA LUMPUR, 24 JULY 2026 —

Listen to this article

DomainFork Audio · read aloud

Headline: Russian Global Webmail Espionage Lead: Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global Webmail Espionage appeared first on Unit 42 . Body: Unit 42 has observed a persistent cyberespionage campaign we track as CL-STA-1114. This activity cluster overlaps with activity from a Russian threat actor tracked by other vendors as Void Blizzard and LAUNDRY BEAR.

Market Impact

Unique to this campaign, the group leveraged zero-click phishing emails that exploit a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform (CVE-2025-66376). The exploit automatically injects a malicious JavaScript payload without requiring recipient interaction. Once executed, the payload exfiltrates sensitive user data, including login credentials, email archives, and search histories. Threat actors continue to actively target unpatched ZCS instances using CVE-2025-66376.

If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team .

The attackers behind CL-STA-1114 have been active since at least 2024 , and this campaign targeting Zimbra servers started in July 2025. Initial access starts with a phishing email that contains either an HTML attachment or embedded HTML in the message text. This lure is designed to catch recipients' attention with news headlines.

Figure 1 shows an example of the lure used and a snippet of the underlying HTML code.

The HTML text contains an obfuscated division with a Base64-encoded script (highlighted in red in Figure 1). The obfuscated section creates an invisible Scalable Vector Graphics (SVG) element that, upon loading, decodes the Base64-encoded script into a JavaScript payload that it injects into the victim’s browser.

When executed, this JavaScript exfiltrates the victim’s Zimbra webmail data to a hard-coded command and control (C2) server. Exfiltrated data includes:

Over the course of this campaign, we observed minimal changes to the JavaScript payload.

Since we began tracking this campaign, there have been at least nine IP addresses and nine domains for the C2 servers. These servers were active for an average of 35.4 days. See the Indicators of Compromise (IoC) section for a list of the IP addresses and domains used in CL-STA-1114 activity.

This campaign activity in CL-STA-1114 illustrates the persistent and evolving threat of state-sponsored cyberespionage. The attacker behind this activity targets widely used mail platforms like Zimbra, posing a risk to critical industries globally.

This research highlights the need for vigilance, proactive patching and advanced threat detection to protect organizations. Network administrators, defenders and security researchers should patch vulnerable systems and use the IoCs below to investigate and strengthen defenses against CL-STA-1114 and similar activity.

Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the Cyber Threat Alliance . Source: Palo Alto Unit 42 Published: 2026-07-23T14:10:53.000Z Region: OSINT Topic: Economy (AI-assisted rewrite, based on the original source)

Suggested Reads

The Computer That Helped Win World War II7/23/2026Aneka Jaringan’s 9M26 PAT Plunges 91.6% To RM0.37 MillionAlpha IVF Declares 0.6 Sen Dividend Despite FY26 PATMI Falls 6.8% To RM53.6 Million

Analyst Consensus — This Week

Neutral6.4/10AI sentiment across 98 stories · not investment advice

The Daily Brief · Free

Five market signals.
Five minutes. Every morning.

AI-curated intelligence on Malaysia, ASEAN, and global markets — before the opening bell.

  • ✓ KLCI, ringgit & sector movers
  • ✓ The AI Edge sentiment read
  • ✓ No spam — one email, weekday mornings

Free daily market briefing. No spam, unsubscribe anytime.

DomainFork

Malaysian financial intelligence — AI-assisted coverage of finance, economics, technology, and open-source data across Malaysia, ASEAN, and the world.

Sections

  • Malaysia
  • ASEAN
  • Asia
  • World
  • Tech
  • Markets

Intelligence

  • AI Daily Briefing
  • OSINT Desk
  • Video
  • Audio

Company

  • About Us
  • Editorial Standards
  • Advertise
  • Contact the Desk

Disclaimer: DomainFork provides financial, economic, technology, and OSINT information for general education and research. AI summaries, sentiment scores, and market data are not investment advice. Consult a licensed professional before making financial decisions.

© 2026 DomainFork. All rights reserved.

Powered by: Codint Technology : codint.io