Russian Espionage Group Exploits Zero-Click Zimbra Flaw to Breach Western Organizations
A Russian state-backed espionage group, tracked under multiple aliases including TA488, CL-STA-1114, LAUNDRY BEAR, and Void Blizzard, exploited a previously unknown stored cross-site scripting (XSS) vulnerability (CVE-2025-66376) in Zimbra’s webmail client to infiltrate Western government and commercial organizations. The campaign, active since at least July 2025, allowed attackers to steal emails, credentials, and two-factor authentication (2FA) recovery codes with minimal user interaction requiring only the viewing of a malicious email.
Exploit Mechanics & Impact
The flaw, affecting Zimbra Collaboration 10.0 (pre-10.0.18) and 10.1 (pre-10.1.13), abused CSS @import handling in the Classic UI to execute JavaScript within an authenticated session. Attackers embedded malicious payloads in HTML emails, often disguised as news digests, which bypassed Zimbra’s sanitizer through tag-splitting a technique that fragmented executable markup to evade detection. Once rendered, the exploit:
- Stole CSRF tokens, browser-saved passwords, and 2FA scratch codes via Zimbra’s APIs.
- Exfiltrated the last 90 days of emails as a TGZ archive over DNS queries to attacker-controlled infrastructure.
- Brute-forced the Global Address List by querying two-character combinations.
- Created app-specific passwords (e.g., "ZimbraWeb") to maintain persistent IMAP/POP3/SMTP access, even after password resets.
Targets & Attribution
The campaign targeted NATO member states, Ukraine, the Commonwealth of Independent States, and Africa, focusing on government, defense, transportation, financial, and scientific sectors, including U.S. nuclear installations. Attackers used Proton Mail accounts and compromised addresses to distribute lures, with nine known C2 domains and IPs rotating every ~35 days.
While Proofpoint observed no activity from TA488 after February 2026, Unit 42 reported ongoing exploitation of unpatched Zimbra instances. Discrepancies in attribution persist Seqrite linked the activity to APT28 with medium confidence, while Dutch intelligence treats LAUNDRY BEAR as a separate actor.
Mitigation & Response
Zimbra patched the flaw on November 6, 2025, and CISA added it to the Known Exploited Vulnerabilities catalog on March 18, 2026. However, the fix does not revoke stolen credentials. Organizations are advised to:
- Upgrade to Zimbra 10.1.13+ (or migrate from unsupported 10.0).
- Audit accounts for unauthorized app-specific passwords, IMAP access, and suspicious SOAP calls.
- Scan for malicious emails using Proofpoint’s YARA rule to detect fragmented
@importpatterns. - Monitor DNS logs for exfiltration attempts tied to known C2 domains.
The advisory warns that the group will likely continue targeting Western email systems, even as patching reduces exposure. The incident underscores the risks of zero-click exploits in widely used collaboration platforms.
Source: https://thehackernews.com/2026/07/russian-espionage-group-exploited.html
NATO cybersecurity rating report: https://www.rankiteo.com/company/nato
Zimbra cybersecurity rating report: https://www.rankiteo.com/company/zimbra
"id": "NATZIM1784838304",
"linkid": "nato, zimbra",
"type": "Vulnerability",
"date": "7/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': ['NATO member states',
'Ukraine',
'Commonwealth of Independent States',
'Africa'],
'location': ['Western countries', 'Ukraine', 'Africa'],
'type': ['Government',
'Defense',
'Transportation',
'Financial',
'Scientific']}],
'attack_vector': 'Zero-click exploit (stored XSS via malicious email)',
'data_breach': {'data_exfiltration': 'Yes (TGZ archives over DNS queries)',
'personally_identifiable_information': 'Yes (credentials, 2FA '
'codes)',
'sensitivity_of_data': 'High (personally identifiable '
'information, government/defense '
'communications)',
'type_of_data_compromised': ['Emails',
'Credentials',
'2FA recovery codes',
'Global Address List']},
'date_detected': '2025-07-01',
'date_publicly_disclosed': '2025-11-06',
'description': 'A Russian state-backed espionage group exploited a previously '
'unknown stored cross-site scripting (XSS) vulnerability '
'(CVE-2025-66376) in Zimbra’s webmail client to infiltrate '
'Western government and commercial organizations. The campaign '
'allowed attackers to steal emails, credentials, and '
'two-factor authentication (2FA) recovery codes with minimal '
'user interaction.',
'impact': {'data_compromised': 'Emails, credentials, 2FA recovery codes, '
'Global Address List, app-specific passwords',
'identity_theft_risk': 'High (stolen credentials and 2FA codes)',
'operational_impact': 'Persistent access to email systems, '
'unauthorized data exfiltration',
'systems_affected': 'Zimbra Collaboration 10.0 (pre-10.0.18) and '
'10.1 (pre-10.1.13)'},
'initial_access_broker': {'backdoors_established': 'App-specific passwords '
'for IMAP/POP3/SMTP access',
'entry_point': 'Malicious emails (Proton Mail and '
'compromised addresses)',
'high_value_targets': 'Government, defense, nuclear '
'installations'},
'investigation_status': 'Ongoing (active exploitation reported by Unit 42)',
'lessons_learned': 'Risks of zero-click exploits in widely used collaboration '
'platforms; importance of timely patching and monitoring '
'for credential abuse',
'motivation': 'State-sponsored espionage',
'post_incident_analysis': {'corrective_actions': 'Patch management, '
'credential audits, enhanced '
'monitoring',
'root_causes': 'Unpatched Zimbra vulnerability '
'(CVE-2025-66376), evasion of '
'sanitizer via tag-splitting'},
'recommendations': ['Upgrade to Zimbra 10.1.13+ or migrate from unsupported '
'versions',
'Audit accounts for unauthorized app-specific passwords '
'and IMAP access',
'Scan for malicious emails using Proofpoint’s YARA rule',
'Monitor DNS logs for exfiltration attempts'],
'references': [{'source': 'Proofpoint'},
{'source': 'Unit 42'},
{'source': 'Seqrite'},
{'source': 'Dutch intelligence'},
{'date_accessed': '2026-03-18',
'source': 'CISA Known Exploited Vulnerabilities catalog'}],
'regulatory_compliance': {'regulatory_notifications': 'CISA Known Exploited '
'Vulnerabilities '
'catalog (March 18, '
'2026)'},
'response': {'containment_measures': 'Upgrade to Zimbra 10.1.13+ or migrate '
'from unsupported 10.0',
'enhanced_monitoring': 'Monitor DNS logs for exfiltration '
'attempts tied to known C2 domains',
'remediation_measures': 'Audit accounts for unauthorized '
'app-specific passwords, IMAP access, '
'and suspicious SOAP calls; scan for '
'malicious emails using YARA rules',
'third_party_assistance': ['Proofpoint',
'Unit 42',
'Seqrite',
'Dutch intelligence']},
'threat_actor': ['TA488',
'CL-STA-1114',
'LAUNDRY BEAR',
'Void Blizzard',
'APT28'],
'title': 'Russian Espionage Group Exploits Zero-Click Zimbra Flaw to Breach '
'Western Organizations',
'type': 'Espionage',
'vulnerability_exploited': 'CVE-2025-66376 (Stored XSS in Zimbra '
'Collaboration)'}