CRBC News
Security

Zimbra Zero‑Day Used in Espionage: Russian TA488 Infected Users Just by Viewing Emails

Zimbra Zero‑Day Used in Espionage: Russian TA488 Infected Users Just by Viewing Emails
Credit: Shutterstock

Proofpoint reports that Russian‑linked cluster TA488 (Laundry Bear/Void Blizzard) exploited an XSS zero‑day in Zimbra (CVE‑2025‑66376) to compromise targets by merely viewing malicious emails. The flaw, rated 7.2/10, was patched in November 2025, but was abused well before the fix. TA488 obtained persistent access and exfiltrated emails, passwords, address books and 2FA tokens, focusing on NATO, Ukrainian government and defence contractors. Public exposure in February 2026 appears to have driven the group offline.

Security researchers at Proofpoint have detailed a long‑running espionage campaign in which a Russia‑linked cluster tracked as TA488 (also known as Laundry Bear or Void Blizzard) exploited a zero‑day cross‑site scripting (XSS) flaw in the Zimbra webmail and collaboration platform to compromise targets across the West.

How The Exploit Worked

The vulnerability, now catalogued as CVE‑2025‑66376, allowed attackers to run malicious code in the context of Zimbra’s web interface. Proofpoint calls the technique a “half‑click exploit” because victims could be infected simply by opening or viewing a malicious message in Zimbra’s webmail — no explicit download or link click required.

What The Attackers Did

After exploitation, TA488 reportedly established persistent access to compromised systems. The intruders harvested and exfiltrated a range of sensitive assets, including:

  • Stored and transmitted email messages
  • Passwords and credential material
  • Address books and directory information
  • Two‑factor authentication tokens and related data

“After successful exploitation, TA488 established persistent access to the systems and exfiltrated emails from the targeted users,” Proofpoint wrote.

Targets and Scope

Proofpoint observed the campaign focusing on NATO organizations, Ukrainian government entities and members of the defence industrial base — indicating an intelligence‑gathering objective rather than opportunistic financial fraud. The same Zimbra flaw has been abused by multiple clusters over the years, but this disclosure highlights TA488’s particular tactics and persistence.

Timeline and Mitigation

Zimbra released a patch for CVE‑2025‑66376 in November 2025; the vulnerability carried a CVSS severity rating of 7.2 (High). Evidence suggests threat actors exploited the flaw well before the fix was available. Researchers observed TA488 activity cease after February 2026, following a public exposure of the group’s infrastructure and methods by security researchers (including a detailed writeup from Seqrite), which likely caused the actors to dismantle older setups.

Key Takeaways

This incident underscores several important lessons for high‑risk organizations:

  • Webmail XSS vulnerabilities can be weaponized for silent compromise — viewing mail in a browser can be enough.
  • Prompt patching and timely configuration hardening are critical for collaboration platforms.
  • Monitoring for unusual account access and rapid threat‑intelligence sharing can disrupt persistent espionage operations.

Administrators using Zimbra or other webmail platforms should ensure patches are applied, review webmail XSS protections, enforce strong multi‑factor authentication practices, and monitor for signs of unauthorized email access or data exfiltration.

Help us improve.

Related Articles

Trending