Protecting Against Zero-Click Attacks
Brief
By Aimee Steele, threat intelligence analyst at Talion Cyber Security
Last month, the UK’s National Cyber Security Centre (NCSC) issued an advisory around a new phishing campaign targeting organisations in the West that was being carried out by the Russian state-sponsored threat actor known as Laundry Bear.
The campaign, saw the threat actors exploiting a zero-day vulnerability in Zimbra Collaboration Suite in order to compromise networks, before gaining persistence, accessing emails, stealing sensitive data and conducting espionage against organisations using vulnerable Zimbra Mailservers.
The advisory from the NCSC was issued in conjunction with advisories from 15 other countries, including the US, Finland, Australia, Denmark and France, and it advised that the threat actors were targeting critical industries in order to steal sensitive information with Russian government backing.
