[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$feA9NuIPoZYiIUCmO9Psw0Ui4pk1aaPZAEI3RbzkIaBs":3},{"article":4,"iocs":54},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":31,"category":32,"article_tags":36},"4013b0fc-3a7b-4d02-8f80-cf8bbdf82789","Russian Hackers Used a Zimbra Zero-Day to Steal Emails Without Link Clicks","russian-hackers-used-a-zimbra-zero-day-to-steal-emails-without-link-clicks-7665d3","Russian hackers from the TA488 group exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims.","Russian-linked TA488 hackers exploited a zero-day vulnerability in Zimbra webmail (CVE-2025-66376) to steal credentials and emails by simply opening or previewing malicious messages. The exploit, used since at least July 2025, required no user interaction beyond viewing the email, allowing malware to collect sensitive data and facilitate further attacks. Zimbra released a patch in November 2025.","Russian hackers exploit Zimbra zero-day to steal emails and credentials without user interaction.","Security Cyber Attacks MalwareRussian Hackers Used a Zimbra Zero-Day to Steal Emails Without Link Clicks Russian hackers from the TA488 group exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims. byWaqasJuly 24, 20263 minute read Listen to this article 0:00 — ← 10s ▶ Play 10s → Speed 0.75× 1× 1.25× 1.5× 2× Voice Loading voices… Press play to start listening Opening or previewing a malicious email was enough for Russian-linked hackers to compromise users of vulnerable Zimbra webmail servers. The campaign required no link click or attachment download, allowing the exploit to run as soon as the message appeared in the webmail client. Proofpoint attributes the activity to TA488, a Russia-aligned espionage group also tracked as Laundry Bear and Void Blizzard. The company released its findings in coordination with reporting from the NSA and FBI’s JSAC, while a joint government advisory described the group as state-supported and focused on collecting information for Russia. According to the advisory (PDF), the group targets included Ukrainian government bodies, US government and defense organizations, nuclear installations, scientific institutions and entities in Europe. Proofpoint said the actor had used the previously unknown Zimbra vulnerability since at least July 2025, at least five months before public disclosure. Opening an Email Triggers the Attack When a recipient opened or previewed the message in a vulnerable Zimbra webmail client, malicious JavaScript embedded in its HTML body executed automatically. The messages used generic business themes and were sent from attacker-controlled Proton Mail addresses or accounts compromised during earlier operations. The flaw, tracked as CVE-2025-66376, affected Zimbra’s handling of HTML and CSS content. Attackers split dangerous code into pieces that passed through the webmail sanitizer, allowing the browser to reconstruct and execute it when displaying the email. Once active, malware tracked by Proofpoint as ZimReaper collected the victim’s email address, browser-saved password, two-factor authentication scratch codes, and information about the Zimbra installation. It also searched the organization’s address directory and attempted to export up to 90 days of email. TA488 then created an application password named “ZimbraWeb,” which could provide continuing mailbox access through IMAP, POP3, or SMTP without requiring the victim’s normal two-factor authentication process. Stolen information was transmitted through DNS requests and web traffic to attacker-controlled servers. Compromised mailboxes also helped the group reach new targets. Messages sent from legitimate accounts were more likely to appear credible, giving TA488 another route for delivering exploit emails to government and commercial organizations. “The messages use generic lures and do not require the targeted user to click on a link or open an attachment. The XSS exploit is embedded directly in the HTML body of the message and fires as soon as the victim opens or previews it in the vulnerable Zimbra webmail client. No further user interaction is required.” Proofpoint Threat Research Team One of the lure “Cooperation Belgian Foundation” emails used by the TA488 group in October 2025 (Image credit: Proofpoint) Zimbra Patch Available Since November 2025 Zimbra patched CVE-2025-66376 in November 2025, with fixes included in ZCS 10.1.13 and 10.0.18. The vulnerability was publicly documented in January 2026, months after TA488 began exploiting it as a zero-day. Administrators should update every exposed Zimbra server and review \u002Fopt\u002Fzimbra\u002Flog\u002Faudit.log for requests that create application passwords, particularly entries named “ZimbraWeb.” The joint advisory also recommends revoking application passwords and 2FA scratch codes, resetting user passwords, and checking for indicators published with the report. Although Proofpoint states it could not independently connect TA488 to Void Blizzard with high confidence from its own telemetry, collaboration with US government partners confirmed the association. Proofpoint has not observed activity from the group since February 2026, but the advisory warns that vulnerable Zimbra installations remain at risk. (Photo by Le Vu on Unsplash) Waqas I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism. View Posts Cyber AttackCyber CrimeCybersecurityFBILaundry BearMalwareNSAProofpointRussiaTA488UkraineVoid BlizzardVulnerabilityZimbraZimbraWebZimReaper Leave a Reply Cancel reply View Comments (0) Related Posts Read More Cyber Crime Malware Phishing Scam Scams and Fraud Security US Congress Dumps Yahoo Mail Over Phishing Attacks Yahoo mail Hammered by Congress for its Inefficiency in Preventing Phishing Attempts Symantec’s newest threat report claims that… byCarolina Read More Security Leaks Data of millions of Japanese sold on underground hacking forums A cybercriminal operating from outside China was found to be selling data of nearly 200 million Japanese users… byWaqas Read More Cyber Crime Phishing Scam Privacy Scams and Fraud Security 7 More Chrome Extensions Hacked via Phishing Scam Google Chrome Extensions on the Radar of Cybercriminals of late- Security Experts identify seven more extensions to be… byWaqas Read More Security Malware New Malware Spotted Corrupts Its Own Headers to Block Analysis Fortinet spots new malware that corrupts its own headers to block forensic analysis, hide behavior, and communicate with its C2 server. byWaqas","https:\u002F\u002Fhackread.com\u002Frussian-hackers-zimbra-0-day-steal-emails-link-clicks\u002F","https:\u002F\u002Fhackread.com\u002Fwp-content\u002Fuploads\u002F2026\u002F07\u002Frussian-hackers-zimbra-0-day-steal-emails-link-clicks.jpg","2026-07-24T11:04:51+00:00","2026-07-24T12:00:20.692091+00:00",9,[18,21,23,25,28],{"name":19,"type":20},"TA488","threat_actor",{"name":22,"type":20},"Laundry Bear",{"name":24,"type":20},"Void Blizzard",{"name":26,"type":27},"Zimbra","product",{"name":29,"type":30},"Proton Mail","vendor","574f766a-fb3f-487c-8d2c-0720ae75471b",{"id":31,"icon":33,"name":34,"slug":35},null,"Zero-day","zero-day",[37,39,44,49],{"category":38},{"id":31,"icon":33,"name":34,"slug":35},{"category":40},{"id":41,"icon":33,"name":42,"slug":43},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":45},{"id":46,"icon":33,"name":47,"slug":48},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":50},{"id":51,"icon":33,"name":52,"slug":53},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[55,59],{"type":56,"value":57,"context":58},"cve","CVE-2025-66376","Zimbra webmail vulnerability exploited by TA488",{"type":48,"value":60,"context":61},"ZimReaper","Malware used by TA488 to collect victim data"]