Russian Hackers Exploit Zimbra Zero-Day to Steal Emails Without Clicking Links

Recent findings revealed a security threat in which hackers linked to Russia exploited vulnerabilities in Zimbra webmail servers. Users could be compromised simply by opening or previewing a malicious email, with no need for any further interaction such as clicking links or downloading attachments. This approach underscores the seamless and insidious nature of the attack.

The security firm Proofpoint attributes this activity to a group known as TA488, also identified as Laundry Bear and Void Blizzard, which is aligned with Russian espionage efforts. Their findings were released in collaboration with intelligence from the NSA and FBI, outlining the state-backed nature of the group’s operations aimed at gathering intelligence for Russia.

According to a joint government advisory, the targeted entities included a range of organizations such as Ukrainian government bodies, U.S. defense institutions, nuclear facilities, and several scientific and commercial organizations throughout Europe. Notably, the previously undisclosed vulnerability has been exploited by the attackers since at least July 2025, well before it was made public.

Opening an Email Triggers the Attack

Upon opening or previewing an email within a vulnerable Zimbra client, malicious JavaScript embedded in the message would execute automatically. The emails often adopted generic business themes and originated from compromised or attacker-controlled Proton Mail accounts.

This vulnerability, identified as CVE-2025-66376, affected Zimbra’s handling of HTML and CSS content. Attackers cleverly fragmented malicious code to bypass webmail security measures, allowing it to be reconstructed and executed in the user’s browser immediately after the email was displayed.

The malware, designated as ZimReaper by Proofpoint, began collecting sensitive information from victims’ accounts—including email addresses, browser-stored passwords, two-factor authentication codes, and data on the Zimbra setup. Additionally, it probed the organization’s address directory and aimed to exfiltrate up to 90 days’ worth of emails.

The TA488 group then generated an application password labeled “ZimbraWeb,” enabling them continued access to compromised mailboxes via IMAP, POP3, or SMTP protocols, bypassing the usual two-factor authentication requirements. Stolen data was sent back to the attackers through DNS requests and web traffic directed to their servers.

Utilizing access to compromised accounts, the attackers could send further messages that appeared legitimate, enhancing their credibility and effectiveness in targeting additional government and commercial entities.

“The messages use generic lures and do not require the targeted user to click on a link or open an attachment. The XSS exploit is embedded directly in the HTML body of the message and fires as soon as the victim opens or previews it in the vulnerable Zimbra webmail client. No further user interaction is required.”

Proofpoint Threat Research Team

One of the lure emails from the TA488 group, titled “Cooperation Belgian Foundation,” used in October 2025 (Image credit: Proofpoint)

Zimbra Patch Available Since November 2025

Zimbra has addressed CVE-2025-66376 with patches issued in November 2025, included in ZCS versions 10.1.13 and 10.0.18. The vulnerability only gained public attention in January 2026, several months after it had been actively exploited by TA488.

Organizations operating exposed Zimbra servers are urged to perform updates and examine audit logs for any requests that create application passwords, especially those labeled “ZimbraWeb.” The advisory also advises revoking any application passwords and two-factor authentication codes, resetting user passwords, and monitoring for specific indicators of compromise detailed in the report.

While Proofpoint noted it could not definitively link TA488 to Void Blizzard based on its telemetry alone, collaborations with U.S. governmental bodies affirmed the connection. Though Proofpoint has not observed recent activity from this group since February 2026, the advisory cautions that vulnerable Zimbra installations still face potential risks.

(Photo by Le Vu on Unsplash)

Source