A Russian state-backed cyber espionage group has been caught exploiting a previously unknown vulnerability in Zimbra’s webmail platform to steal sensitive emails and account credentials from government and commercial organizations across Western countries.

According to a joint advisory released by the U.S. National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), international partners, Palo Alto Networks Unit 42, and Proofpoint, the campaign has been active since at least July 2025.

The attackers exploited a stored cross-site scripting (XSS) vulnerability tracked as CVE-2025-66376 in Zimbra’s Classic Web Client. The flaw allowed a specially crafted HTML email to execute malicious JavaScript automatically when the message was viewed or previewed in a vulnerable webmail session. Victims did not need to click links or download attachments, making the attack effectively zero-click.

Security researchers found that the malicious code inherited the authenticated user’s webmail permissions, enabling attackers to access the victim’s mailbox directly. The malware was capable of stealing the last 90 days of emails, downloading the organization’s entire Global Address List, collecting browser-saved passwords, retrieving two-factor authentication recovery codes, and gathering Zimbra account information. Stolen data was then exfiltrated through attacker-controlled infrastructure using DNS requests.

The campaign has been tracked by different names across the cybersecurity community, including TA488, CL-STA-1114, LAUNDRY BEAR, and Void Blizzard. While researchers differ on the exact attribution, government agencies assess the activity to be linked to a Russian state-sponsored espionage operation targeting Western interests.

READ
U.S. Seizes Over 1,000 Illegal Streaming Sites During FIFA World Cup 2026 Crackdown

Proofpoint reported that the attackers delivered malicious emails from Proton Mail accounts they controlled as well as previously compromised email accounts. Many messages appeared to be harmless news digests or routine communications, helping them evade suspicion. The exploit was hidden inside the HTML content using a tag-splitting technique that bypassed Zimbra’s built-in security filters before reconstructing executable code inside the victim’s browser.

Researchers named the JavaScript payload ZimReaper, which not only harvested emails and credentials but also created a new application-specific password named ZimbraWeb. This allowed attackers to maintain long-term access to affected accounts through IMAP, POP3, or SMTP even if users later changed their passwords. In some cases, the malware also enabled IMAP on accounts where it had previously been disabled.

The campaign targeted organizations across government, defense, transportation, finance, scientific research, and critical infrastructure sectors in NATO member countries, Ukraine, the Commonwealth of Independent States, Africa, and the United States. Among the reported targets were government agencies, defense contractors, scientific institutions, and organizations connected to the nuclear sector. Researchers did not disclose the identities or number of compromised organizations.

The vulnerability affects Zimbra Collaboration versions 10.0 before 10.0.18 and 10.1 before 10.1.13. Zimbra released a security fix in November 2025, and CISA later added the flaw to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation. However, researchers warn that applying the update alone does not remove attacker access if credentials were already stolen.

READ
Adobe Acrobat Chrome Extension Flaw Could Expose WhatsApp Web Conversations

Security experts recommend upgrading all supported Zimbra deployments immediately, moving away from end-of-life 10.0 releases, resetting passwords for potentially affected accounts, revoking active sessions, regenerating two-factor authentication recovery codes, and removing unauthorized application-specific passwords. Administrators are also advised to inspect audit logs for suspicious account activity, monitor for unexpected IMAP access, and block the published command-and-control domains associated with the campaign.

Although Proofpoint says it has not observed activity from the group since February 2026, government agencies and Palo Alto Networks warn that attackers continue targeting unpatched Zimbra servers and are likely to keep exploiting email platforms in future espionage operations.


Buy ExpressVPN with PayPal or Credit Card

Advertisement