INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Zimbra Zero-Day Exploit Used for Email Theft
| 2026-07-24 11:04 HIGH HIGHExecutive Summary AI-generated
The Russian-linked hackers exploited a previously unknown vulnerability in Zimbra webmail servers to steal emails without requiring link clicks, compromising users and potentially collecting sensitive information for Russia. The attack was attributed to TA488, a state-supported espionage group also known as Laundry Bear and Void Blizzard. Proofpoint attributes the activity to this group since at least July 2025, with the company releasing its findings in coordination with reports from the NSA and FBI's Joint Security Assistance Center (JSAC).
Technical Mitigations AI-generated
* Use up-to-date and patched versions of Zimbra, such as ZCS 10.1.13 or 10.0.18, to ensure that the known CVE-2025-66376 vulnerability is fixed.
* Implement a web application firewall (WAF) with advanced threat protection capabilities to detect and block malicious traffic before it reaches the vulnerable server.
* Regularly review audit logs for requests that create application passwords, particularly entries named "ZimbraWeb", which can be used by Russian-linked hackers to gain access to compromised mailboxes.
* Consider revoking 2-factor authentication (2FA) scratch codes and resetting user passwords on exposed Zimbra servers to prevent attackers from using stolen credentials.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-66376CVE-2025-66376
Target & Sectors
BENELUX
BENELUX
FIVE_EYES
FIVE_EYES
AFRICA
AFRICA
EUROPE
EUROPE
CIS
CIS
NORTH_AMERICA
NORTH_AMERICA
transportationtransportation
governmentgovernment
maritimemaritime
defensedefense
Incident Timeline
May 2025
Russian hackers used a Zimbra zero-day to steal emails without link clicks.
Click on any entity below to view its context and source!
industry
Government
In its own
advisory
, Proofpoint said the group had compromised “government, high science, and defense industrial base targets in the United States.”
Laundry Bear was
first identified
in May 2025 by Dutch intelligence agencies, which blamed the group for a series of hacks in the Netherlands, including on the national police.
industry
Defense
In its own
advisory
, Proofpoint said the group had compromised “government, high science, and defense industrial base targets in the United States.”
Laundry Bear was
first identified
in May 2025 by Dutch intelligence agencies, which blamed the group for a series of hacks in the Netherlands, including on the national police.
source_region
United States
In its own
advisory
, Proofpoint said the group had compromised “government, high science, and defense industrial base targets in the United States.”
Laundry Bear was
first identified
in May 2025 by Dutch intelligence agencies, which blamed the group for a series of hacks in the Netherlands, including on the national police.
source_region
Netherlands
In its own
advisory
, Proofpoint said the group had compromised “government, high science, and defense industrial base targets in the United States.”
Laundry Bear was
first identified
in May 2025 by Dutch intelligence agencies, which blamed the group for a series of hacks in the Netherlands, including on the national police.
attribution
Proofpoint
In its own
advisory
, Proofpoint said the group had compromised “government, high science, and defense industrial base targets in the United States.”
Laundry Bear was
first identified
in May 2025 by Dutch intelligence agencies, which blamed the group for a series of hacks in the Netherlands, including on the national police.
at least July 2025
Russian hackers used a previously unknown Zimbra zero-day vulnerability to steal emails without link clicks.
Click on any entity below to view its context and source!
vulnerability
CVE-2025-66376
Since at least July 2025, the group has been deploying a novel exploit against the
CVE-2025-66376
vulnerability in which a malicious JavaScript payload is hidden in emails sent from previously compromised email accounts.
tactic
T1059.007 - JavaScript
Since at least July 2025, the group has been deploying a novel exploit against the
CVE-2025-66376
vulnerability in which a malicious JavaScript payload is hidden in emails sent from previously compromised email accounts.
July 2025
Russian hackers used a Zimbra zero-day vulnerability to steal emails without requiring two-factor authentication.
Click on any entity below to view its context and source!
organisation
CSS
The flaw, tracked as
CVE-2025-66376
, affected Zimbra’s handling of HTML and CSS content.
organisation
HTML
Opening an Email Triggers the Attack
When a recipient opened or previewed the message in a vulnerable Zimbra webmail client, malicious JavaScript embedded in its HTML body executed automatically.
organisation
ZimReaper
Once active, malware tracked by Proofpoint as ZimReaper collected the victim’s email address, browser-saved password, two-factor authentication scratch codes, and information about the Zimbra installation.
organisation
ZimbraWeb
TA488 then created an application password named “ZimbraWeb,” which could provide continuing mailbox access through IMAP, POP3, or SMTP without requiring the victim’s normal two-factor authentication process.
organisation
IMAP
TA488 then created an application password named “ZimbraWeb,” which could provide continuing mailbox access through IMAP, POP3, or SMTP without requiring the victim’s normal two-factor authentication process.
organisation
SMTP
TA488 then created an application password named “ZimbraWeb,” which could provide continuing mailbox access through IMAP, POP3, or SMTP without requiring the victim’s normal two-factor authentication process.
organisation
DNS
Stolen information was transmitted through DNS requests and web traffic to attacker-controlled servers.
October 2025
Russian hackers used a Zimbra zero-day vulnerability to steal emails without requiring link clicks.
Click on any entity below to view its context and source!
vulnerability
CVE-2025-66376
Proofpoint Threat Research Team
One of the lure “Cooperation Belgian Foundation” emails used by the TA488 group in October 2025 (Image credit: Proofpoint)
Zimbra Patch Available Since November 2025
Zimbra patched CVE-2025-66376 in November 2025, with fixes included in ZCS 10.1.13 and 10.0.18.
organisation
Proofpoint Threat Research Team
Proofpoint Threat Research Team
One of the lure “Cooperation Belgian Foundation” emails used by the TA488 group in October 2025 (Image credit: Proofpoint)
Zimbra Patch Available Since November 2025
Zimbra patched CVE-2025-66376 in November 2025, with fixes included in ZCS 10.1.13 and 10.0.18.
organisation
CVE-2025
Proofpoint Threat Research Team
One of the lure “Cooperation Belgian Foundation” emails used by the TA488 group in October 2025 (Image credit: Proofpoint)
Zimbra Patch Available Since November 2025
Zimbra patched CVE-2025-66376 in November 2025, with fixes included in ZCS 10.1.13 and 10.0.18.
organisation
ZCS 10.1.13
Proofpoint Threat Research Team
One of the lure “Cooperation Belgian Foundation” emails used by the TA488 group in October 2025 (Image credit: Proofpoint)
Zimbra Patch Available Since November 2025
Zimbra patched CVE-2025-66376 in November 2025, with fixes included in ZCS 10.1.13 and 10.0.18.
November 2025
Russian hackers used a Zimbra zero-day vulnerability to steal emails without link clicks in October 2025.
Click on any entity below to view its context and source!
vulnerability
CVE-2025-66376
Proofpoint Threat Research Team
One of the lure “Cooperation Belgian Foundation” emails used by the TA488 group in October 2025 (Image credit: Proofpoint)
Zimbra Patch Available Since November 2025
Zimbra patched CVE-2025-66376 in November 2025, with fixes included in ZCS 10.1.13 and 10.0.18.
organisation
Proofpoint Threat Research Team
Proofpoint Threat Research Team
One of the lure “Cooperation Belgian Foundation” emails used by the TA488 group in October 2025 (Image credit: Proofpoint)
Zimbra Patch Available Since November 2025
Zimbra patched CVE-2025-66376 in November 2025, with fixes included in ZCS 10.1.13 and 10.0.18.
organisation
CVE-2025
Proofpoint Threat Research Team
One of the lure “Cooperation Belgian Foundation” emails used by the TA488 group in October 2025 (Image credit: Proofpoint)
Zimbra Patch Available Since November 2025
Zimbra patched CVE-2025-66376 in November 2025, with fixes included in ZCS 10.1.13 and 10.0.18.
organisation
ZCS 10.1.13
Proofpoint Threat Research Team
One of the lure “Cooperation Belgian Foundation” emails used by the TA488 group in October 2025 (Image credit: Proofpoint)
Zimbra Patch Available Since November 2025
Zimbra patched CVE-2025-66376 in November 2025, with fixes included in ZCS 10.1.13 and 10.0.18.
organisation
APT
The campaign, carried out by the advanced persistent threat (APT) group Laundry Bear, targets Zimbra Collaboration Suite’s webmail platform and exploits a
vulnerability
that was patched in November 2025.
January 2026
Russian hackers exploited a recently discovered Zimbra zero-day vulnerability to steal emails without requiring link clicks.
February 2026
Russian hackers exploited a recently discovered zero-day vulnerability in Zimbra email servers to gain unauthorized access and steal emails without triggering link clicks.
March 2026
Russian hackers used a zero-day vulnerability in Zimbra webmail to steal emails without requiring users to click on malicious links.
Click on any entity below to view its context and source!
target_region
Ukraine
In March 2026, the cybersecurity firm Seqrite
described
a zero-click phishing campaign exploiting Zimbra webmail that
compromised a Ukrainian maritime agency
.
tactic
Phishing
In March 2026, the cybersecurity firm Seqrite
described
a zero-click phishing campaign exploiting Zimbra webmail that
compromised a Ukrainian maritime agency
.
industry
Maritime
In March 2026, the cybersecurity firm Seqrite
described
a zero-click phishing campaign exploiting Zimbra webmail that
compromised a Ukrainian maritime agency
.
2026/07/24
Russian state-aligned hackers used a Zimbra zero-day vulnerability to steal emails without link clicks.
Click on any entity below to view its context and source!
organisation
NATO
According to the
advisory
, the hackers carried out “extensive” targeting of Ukrainian entities before training their sights on U.S. and NATO organizations — evidence of “an increasing trend within Russian cyber threat groups to target Ukrainian users first—both as a priority target and as a testbench for malicious cyber techniques before broader global deployment.”
organisation
TA488
Proofpoint attributes the activity to TA488, a Russia-aligned espionage group also tracked as Laundry Bear and Void Blizzard.
organisation
Laundry Bear
Proofpoint attributes the activity to TA488, a Russia-aligned espionage group also tracked as Laundry Bear and Void Blizzard.
organisation
Palo Alto Networks’ Unit
Palo Alto Networks’ Unit 42, which also published a
report
Thursday on the campaign, said the hackers targeted the defense and transportation sectors, as well as financial organizations in NATO member states, Ukraine, Commonwealth of Independent States countries and Africa.
organisation
Commonwealth of Independent States
Palo Alto Networks’ Unit 42, which also published a
report
Thursday on the campaign, said the hackers targeted the defense and transportation sectors, as well as financial organizations in NATO member states, Ukraine, Commonwealth of Independent States countries and Africa.
organisation
Microsoft
According to Microsoft, it has been active since at least 2024.
Intelligence Sources
TheRecord
2026-07-23
HackRead
2026-07-24
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-25T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
17x
organisation
Identified Entity
TA488
entity
9x
timeline
Temporal Reference
October 2025
date
6x
target region
Target Country
Russian Federation
country
5x
attribution
Attributing Entity
NSA
authority
4x
source region
Origin Country
Russian Federation
country
4x
industry
Targeted Sector
Government
sector
3x
tactic
Cyber Operation Type
Espionage
tactic
3x
target region
Target Region
EUROPE
region
Contextual Telemetry
Context Block
2 METRICS
vulnerability
Exploited CVE
CVE-2025-66376
cve
tactic
MITRE ATT&CK Technique
T1059.007 - JavaScript
technique
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.