Russian State-Sponsored Group Exploits Zimbra Vulnerability for Espionage

A sophisticated Russian state-sponsored espionage group has been systematically compromising Western email accounts for months, leveraging a previously undisclosed vulnerability within Zimbra’s widely used webmail client. The attackers, identified by multiple cybersecurity agencies and research firms, have successfully exfiltrated sensitive data, including recent emails, contact lists, and authentication credentials, from targeted government and commercial organizations. This campaign, which has been ongoing since at least July 2025, underscores the persistent threat posed by nation-state actors to critical infrastructure and sensitive data.
The vulnerability, designated CVE-2025-66376, resides in the Classic User Interface of Zimbra Collaboration and exploits a stored cross-site scripting (XSS) flaw. The exploit mechanism is particularly insidious, requiring only the victim to view a specially crafted email within a vulnerable Zimbra client to initiate the attack. This "view-based exploit," as described in a joint advisory from the U.S. National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agency (CISA), bypasses traditional security measures that often depend on user interaction like clicking a link or opening an attachment.
The Anatomy of the Attack
The technical details of the exploit reveal a clever manipulation of HTML and CSS within email messages. The threat actors embed malicious JavaScript code within an svg onload tag, cleverly disguised and fragmented using CSS @import directives and HTML comments. Zimbra’s email sanitizer, designed to strip potentially harmful markup, fails to recognize these fragmented components as executable. When the email is rendered in the webmail client, the sanitizer removes the disruptive @import sequences, allowing the remaining code fragments to reassemble into a functional <svg onload=eval(atob(...))> command. This command then executes JavaScript within the context of the authenticated user’s session, granting the attackers the same access privileges as the victim.
The payload, tracked by Proofpoint as ZimReaper, is designed to be highly effective in its data extraction. Upon successful execution, it systematically pilfers several critical pieces of information:

- Browser-Saved Passwords: This includes any credentials stored by the user’s web browser for accessing various online services.
- Two-Factor Authentication (2FA) Recovery Codes: These "scratch codes" are often used as a fallback mechanism for regaining access to accounts when primary 2FA methods are unavailable.
- Cross-Site Request Forgery (CSRF) Tokens: These tokens are crucial for preventing certain types of web attacks and can be leveraged by attackers to impersonate users.
- Zimbra Version Information: This data helps the attackers identify further potential vulnerabilities or tailor their subsequent attacks.
- Last 90 Days of Emails: The attackers are able to extract a significant portion of the victim’s recent email history.
- Entire Email Directory: This encompasses the organization’s complete address book, providing valuable intelligence for further targeting.
Furthermore, the payload utilizes the Zimbra platform’s own APIs to exfiltrate this stolen data through DNS queries to the attackers’ command-and-control (C2) infrastructure. The attackers also engage in brute-forcing the Global Address List (GAL), systematically querying every two-character combination to reconstruct the full directory. Finally, the payload archives 90 days of the victim’s mail into a TGZ file for exfiltration.
A particularly concerning aspect of the attack is the payload’s ability to create an application-specific password, named ZimbraWeb, through the CreateAppSpecificPasswordRequest API. This newly generated credential can grant IMAP, POP3, or SMTP access to the compromised mailbox, bypassing two-factor authentication entirely. This capability allows the attackers to maintain persistent access even if the original compromised password is changed.
Timeline of Exploitation and Disclosure
The campaign’s timeline reveals a significant period of undetected activity. Palo Alto Networks’ Unit 42 and Proofpoint, both prominent cybersecurity research firms, have been tracking the threat actors. Proofpoint, which attributes the activity to the group it tracks as TA488, stated that the group exploited CVE-2025-66376 as an unknown vulnerability for at least five months during 2025, prior to the official patch being released. This means organizations were vulnerable and potentially compromised for an extended period without awareness.
The vulnerability was officially patched by Zimbra on November 6, 2025, with updates to Zimbra Collaboration 10.0.18 and 10.1.13. However, the severity of the exploit led to its inclusion in the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog on March 18, 2026. This inclusion signifies that the vulnerability has been actively exploited in the wild and poses a significant risk to organizations.
The joint advisory, published by the NSA, CISA, and international partners on Thursday, aims to alert organizations to the ongoing threat and provide guidance on mitigation. The advisory highlights that the exploit requires only a user to view a malicious email in a vulnerable client, emphasizing the "zero-click" nature of the attack as described by Unit 42. While the National Vulnerability Database (NVD) scores the vulnerability at CVSS 6.1, classifying it as requiring user interaction, MITRE’s score of 7.2 and the descriptions from researchers indicate that simply rendering the email is sufficient for exploitation.

Affected Versions and Mitigation Strategies
The vulnerability affects Zimbra Collaboration versions 10.0 prior to 10.0.18 and 10.1 prior to 10.1.13. Zimbra 10.0 reached its end-of-life on December 31, 2025, making version 10.0.18 an essential, albeit temporary, patching floor. The latest stable release of the 10.1 series is 10.1.20, which includes fixes for four additional stored XSS vulnerabilities in the Classic Web Client, underscoring Zimbra’s ongoing efforts to address security weaknesses.
For organizations still running Zimbra 10.0, an immediate upgrade to a supported 10.1 build is strongly recommended. For those on 10.1, upgrading to at least 10.1.13 is crucial. However, patching the software is only the first step. The advisory strongly recommends a thorough review of affected accounts.
Key mitigation steps for compromised organizations include:
- Password Resets: All users who may have opened or previewed a malicious email in a vulnerable Classic UI session should have their passwords reset.
- Invalidate Active Sessions: Existing authenticated sessions for potentially compromised users should be terminated.
- Regenerate 2FA Scratch Codes: Any 2FA recovery codes that may have been compromised should be invalidated and new ones generated.
- Scrutinize Unopened Messages: Emails that landed in mailboxes but were not opened should be carefully examined for the characteristic fragmented
@importpattern. Proofpoint has released a YARA rule to help identify these malicious messages.
It is critical to understand that applying the patch does not automatically revoke credentials that the payload may have already stolen. The creation of application-specific passwords, for instance, can persist even after a password reset. Researchers from Seqrite, who analyzed a similar incident involving a Ukrainian state hydrology agency in January, noted that "app-specific passwords survive password resets," further emphasizing the need for comprehensive account review.
Attribution and the Broader Threat Landscape
The attribution of this campaign to a Russian state-sponsored group is supported by multiple sources. The NSA and CISA advisory lists several names used in the cybersecurity community for these actors, including LAUNDRY BEAR, Void Blizzard, CL-STA-1114 (used by Unit 42), and TA488 (used by Proofpoint). While cautioning that these names may not always refer to the exact same entity, U.S. government partners have confirmed the association of TA488 with Void Blizzard.

Proofpoint’s telemetry indicates that TA488 was active from July 2025 through February 2026, with their infrastructure being actively targeted. The group’s infrastructure, identified by Unit 42, consisted of at least nine C2 IP addresses and nine domains, with each server operational for an average of 35.4 days. Seqrite attributed its January incident to APT28 with medium confidence, while Dutch intelligence, which uses the name LAUNDRY BEAR, considers it and APT28 as separate actors. This divergence in attribution highlights the complexity of tracking and definitively identifying state-sponsored cyber actors, who often employ evolving tactics and infrastructure.
The targeted sectors and regions paint a grim picture of the group’s strategic interests. Organizations across NATO member states, Ukraine, the Commonwealth of Independent States, and Africa have been targeted. Within the United States, government agencies, scientific institutions, defense industrial base entities, and even nuclear installations have been identified as targets. This broad scope underscores the pervasive nature of the threat and the wide range of sensitive information the group seeks to acquire.
Persistent Threat and Future Implications
The ongoing nature of this campaign, even after disclosure and patching, raises significant concerns. While Proofpoint noted a cessation of activity from TA488 since February 2026, potentially linked to the group dismantling its infrastructure following disclosures, Unit 42 has indicated that threat actors continue to actively target unpatched Zimbra Collaboration Suite (ZCS) instances. The joint advisory warns of ongoing activity and predicts that the group will likely continue targeting Zimbra and other Western email systems, even as organizations implement patches.
The implications of this sustained espionage campaign are far-reaching. For governments, the compromise of sensitive communications can undermine national security, diplomatic efforts, and military operations. For commercial entities, the theft of intellectual property, financial data, and customer information can lead to significant economic losses, reputational damage, and competitive disadvantage. The ability of the attackers to maintain persistent access through application-specific passwords highlights the persistent challenge of fully eradicating a compromise once it has occurred.
The incident serves as a stark reminder of the critical importance of robust cybersecurity practices, including timely patching, vigilant monitoring, and comprehensive incident response plans. The complexity of attribution also underscores the need for continued international cooperation and information sharing among cybersecurity agencies and private sector researchers to effectively counter sophisticated nation-state threats. As the digital landscape continues to evolve, the threat actors’ ability to discover and exploit zero-day vulnerabilities, coupled with their sophisticated exfiltration techniques, demands a proactive and adaptive defense strategy from all organizations. The continued vigilance of defenders, coupled with swift action on patching and account review, will be crucial in mitigating the ongoing risks posed by advanced persistent threats.







