Advisory on New Zero-Click Phishing Campaign Targeting Western Organizations

The NCSC and international partners have identified a new zero-click phishing campaign by Russian state-supported actors targeting Western organizations, particularly those using Zimbra Collaboration Suite. Organizations are advised to enhance their cybersecurity measures.

Editorial image representing cybersecurity concepts in a digital landscape.

Key points

  • Russian state-supported actors are using a zero-click exploit called 'beehive' to compromise email systems.
  • The campaign primarily targets organizations using Zimbra Collaboration Suite.
  • Immediate patching of vulnerabilities and enhanced network monitoring are recommended.
  • The techniques used may be adapted to exploit other email systems in the future.
  • Organizations are encouraged to sign up for early warning services to stay informed.

Overview

The National Cyber Security Centre (NCSC) and its international partners have issued a warning regarding a new phishing campaign orchestrated by Russian state-supported actors. This campaign employs a zero-click exploit known as 'beehive' to gain unauthorized access to email systems, particularly targeting organizations that utilize the Zimbra Collaboration Suite.

Implications

Unlike traditional phishing methods that require user interaction, the 'beehive' technique allows attackers to compromise systems simply by the recipient viewing a malicious email. This poses a significant risk to sensitive data and operational integrity. Organizations in sectors such as defense, government, and technology are particularly vulnerable.

Recommended Actions

To mitigate the risks associated with this campaign, organizations are advised to take the following steps:

  • Immediately patch any vulnerabilities in the Zimbra Collaboration Suite.
  • Enhance network monitoring capabilities to detect unusual activities.
  • Stay informed about potential threats by signing up for early warning services.
  • Educate employees about the risks of phishing and the importance of cybersecurity hygiene.
  • Regularly review and update incident response plans to address potential breaches effectively.

What to do now

  1. Immediately patch vulnerabilities in the Zimbra Collaboration Suite.
  2. Enhance network monitoring capabilities to detect unusual activities.
  3. Sign up for early warning services to stay informed about threats.
  4. Educate employees on phishing risks and cybersecurity hygiene.
  5. Regularly review and update incident response plans.
Need help acting on this?

Our consultants can assess your exposure and map the change to your controls and evidence.

Talk to an expert

Regulatory updates in your inbox

SAMA, NCA and SDAIA changes and what they mean for your institution — once a month.

We confirm by e-mail; unsubscribe any time.

Schedule a Free Assessment