INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Zimbra Zero-Day Exploit Used for Email Theft

| 2026-07-24 11:04 HIGH HIGH
Executive Summary AI-generated
The Russian-linked hackers exploited a previously unknown vulnerability in Zimbra webmail servers to steal emails without requiring link clicks, compromising users and potentially collecting sensitive information for Russia. The attack was attributed to TA488, a state-supported espionage group also known as Laundry Bear and Void Blizzard. Proofpoint attributes the activity to this group since at least July 2025, with the company releasing its findings in coordination with reports from the NSA and FBI's Joint Security Assistance Center (JSAC).
Technical Mitigations AI-generated
* Use up-to-date and patched versions of Zimbra, such as ZCS 10.1.13 or 10.0.18, to ensure that the known CVE-2025-66376 vulnerability is fixed. * Implement a web application firewall (WAF) with advanced threat protection capabilities to detect and block malicious traffic before it reaches the vulnerable server. * Regularly review audit logs for requests that create application passwords, particularly entries named "ZimbraWeb", which can be used by Russian-linked hackers to gain access to compromised mailboxes. * Consider revoking 2-factor authentication (2FA) scratch codes and resetting user passwords on exposed Zimbra servers to prevent attackers from using stolen credentials.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-66376CVE-2025-66376
Target & Sectors
BENELUX BENELUX FIVE_EYES FIVE_EYES AFRICA AFRICA EUROPE EUROPE CIS CIS NORTH_AMERICA NORTH_AMERICA transportationtransportation governmentgovernment maritimemaritime defensedefense
Incident Timeline
‎May 2025
Russian hackers used a Zimbra zero-day to steal emails without link clicks.
industry Government
industry Defense
source_region United States
source_region Netherlands
attribution Proofpoint
‎at least July 2025
Russian hackers used a previously unknown Zimbra zero-day vulnerability to steal emails without link clicks.
vulnerability CVE-2025-66376
tactic T1059.007 - JavaScript
‎July 2025
Russian hackers used a Zimbra zero-day vulnerability to steal emails without requiring two-factor authentication.
organisation CSS
organisation HTML
organisation ZimReaper
organisation ZimbraWeb
organisation IMAP
organisation SMTP
organisation DNS
‎October 2025
Russian hackers used a Zimbra zero-day vulnerability to steal emails without requiring link clicks.
vulnerability CVE-2025-66376
organisation Proofpoint Threat Research Team
organisation CVE-2025
organisation ZCS 10.1.13
‎November 2025
Russian hackers used a Zimbra zero-day vulnerability to steal emails without link clicks in October 2025.
vulnerability CVE-2025-66376
organisation Proofpoint Threat Research Team
organisation CVE-2025
organisation ZCS 10.1.13
organisation APT
‎January 2026
Russian hackers exploited a recently discovered Zimbra zero-day vulnerability to steal emails without requiring link clicks.
‎February 2026
Russian hackers exploited a recently discovered zero-day vulnerability in Zimbra email servers to gain unauthorized access and steal emails without triggering link clicks.
‎March 2026
Russian hackers used a zero-day vulnerability in Zimbra webmail to steal emails without requiring users to click on malicious links.
target_region Ukraine
tactic Phishing
industry Maritime
‎2026/07/24
Russian state-aligned hackers used a Zimbra zero-day vulnerability to steal emails without link clicks.
organisation NATO
organisation TA488
organisation Laundry Bear
organisation Palo Alto Networks’ Unit
organisation Commonwealth of Independent States
organisation Microsoft