International agencies have issued a joint warning about a cyber campaign linked to Russian state-backed hackers that is targeting Western organizations. The activity centers on a zero-click attack, a method that can work without the recipient opening a message or interacting with a phishing email.

The alert says the campaign is exploiting a critical flaw in Zimbra Collaboration Suite, a widely used email and collaboration platform. Because the attack does not depend on normal user action, it raises the risk for organizations that rely on email systems as a core part of daily operations.

Zero-click techniques are especially concerning because they can reduce the usual signs of compromise and make attacks harder to stop through user awareness alone. In this case, the reported tactic appears designed to give threat actors a way into targeted environments while bypassing the need for a victim to click a malicious link or attachment.

The warning highlights the growing focus on email infrastructure as a strategic target in state-linked cyber operations. For organizations using Zimbra Collaboration Suite, the reported exploitation underlines the need to review exposure to critical vulnerabilities and assess whether their systems could be affected by this latest hacking campaign.