SUBJECT PROFILE
Russian state-sponsored APT group named by the Netherlands AIVD/MIVD, publicly attributed in a major joint CISA/NSA/FBI advisory (AA26-204A) on July 23, 2026. The group exploited CVE-2025-66376, a stored XSS zero-day in Zimbra Collaboration Suite's Classic UI, deploying a custom capability called 'Ulej' (Russian: beehive) to silently exfiltrate email, 2FA tokens, and app-specific passwords — requiring only that a victim view a malicious email to trigger exploitation. A notable OPSEC trait is the use of Mullvad VPN services to obscure origin, and the advisory noted possible AI-assisted development in Ulej's codebase.
Cyber espionage; covert acquisition of email data from Western government and commercial targets on behalf of the Russian Federation
OPERATIONAL HISTORY
Zero-day exploitation (CVE-2025-66376 Zimbra XSS), view-based exploit delivery (no user click required), custom exfiltration tool 'Ulej', 2FA token harvesting, app-specific password minting, IMAP persistence implant, password spraying, adversary-in-the-middle phishing, session-token replay, Mullvad VPN abuse for operational cover
KNOWN INFRASTRUCTURE
Websites impersonating legitimate services (per CISA IOCs), Mullvad VPN exit nodes, custom 'Ulej' data exfiltration capability, SOAP API abuse for Zimbra enumeration (GetInfoRequest, GetScratchCodesRequest, GetDeviceStatusRequest, GetOAuthConsumersRequest)