Threat Management, Phishing, Threat Intelligence

UK issues alert over Russian zero-click email attacks

Binary code on flag of Russia. Program source code or Hacker concept on Russian flag. Russia digital technology security, hacking or programming

The UK's National Cyber Security Centre (NCSC) issued an alert regarding a new 'zero-click' threat campaign orchestrated by Russian state-backed hackers targeting organizations across critical sectors, according to a recent report by IT Pro.

The 'beehive' attacks, attributed to the 'Laundry Bear' threat group, exploit vulnerable versions of Zimbra Collaboration Suite (ZCS) software to steal email correspondence. These zero-click attacks compromise users simply by viewing a malicious email, bypassing traditional security measures. Targeted sectors include defense, education, energy, technology, law enforcement, and government agencies. Notably, the techniques were extensively trialled on Ukrainian organizations before being deployed against Western nations. The NCSC urges ZCS users to apply immediate patches and enhance network monitoring. Analysis suggests these methods could be adapted for other email software, posing a broader risk. Experts emphasize the need for rapid software patching and layered technical defenses, as zero-click exploits offer attackers a silent, invisible entry point, circumventing human security training and making them a significant challenge for defenders.

Source: IT Pro

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds