Opening or previewing a malicious e-mail was sufficient for Russian-linked hackers to compromise customers of weak Zimbra webmail servers. The marketing campaign required no hyperlink click on or attachment obtain, permitting the exploit to run as quickly because the message appeared within the webmail shopper.
Proofpoint attributes the exercise to TA488, a Russia-aligned espionage group additionally tracked as Laundry Bear and Void Blizzard. The corporate launched its findings in coordination with reporting from the NSA and FBI’s JSAC, whereas a joint authorities advisory described the group as state-supported and targeted on accumulating info for Russia.
In accordance with the advisory (PDF), the group targets included Ukrainian authorities our bodies, US authorities and protection organizations, nuclear installations, scientific establishments and entities in Europe. Proofpoint stated the actor had used the beforehand unknown Zimbra vulnerability since a minimum of July 2025, a minimum of 5 months earlier than public disclosure.
Opening an Electronic mail Triggers the Assault
When a recipient opened or previewed the message in a weak Zimbra webmail shopper, malicious JavaScript embedded in its HTML physique executed mechanically. The messages used generic enterprise themes and had been despatched from attacker-controlled Proton Mail addresses or accounts compromised throughout earlier operations.
The flaw, tracked as CVE-2025-66376, affected Zimbra’s dealing with of HTML and CSS content material. Attackers cut up harmful code into items that handed via the webmail sanitizer, permitting the browser to reconstruct and execute it when displaying the e-mail.
As soon as lively, malware tracked by Proofpoint as ZimReaper collected the sufferer’s e-mail tackle, browser-saved password, two-factor authentication scratch codes, and details about the Zimbra set up. It additionally searched the group’s tackle listing and tried to export as much as 90 days of e-mail.
TA488 then created an software password named “ZimbraWeb,” which may present persevering with mailbox entry via IMAP, POP3, or SMTP with out requiring the sufferer’s regular two-factor authentication course of. Stolen info was transmitted via DNS requests and net visitors to attacker-controlled servers.
Compromised mailboxes additionally helped the group attain new targets. Messages despatched from reliable accounts had been extra more likely to seem credible, giving TA488 one other route for delivering exploit emails to authorities and industrial organizations.
“The messages use generic lures and don’t require the focused person to click on on a hyperlink or open an attachment. The XSS exploit is embedded immediately within the HTML physique of the message and fires as quickly because the sufferer opens or previews it within the weak Zimbra webmail shopper. No additional person interplay is required.”
Proofpoint Risk Analysis Group

Zimbra Patch Accessible Since November 2025
Zimbra patched CVE-2025-66376 in November 2025, with fixes included in ZCS 10.1.13 and 10.0.18. The vulnerability was publicly documented in January 2026, months after TA488 started exploiting it as a zero-day.
Directors ought to replace each uncovered Zimbra server and evaluation /decide/zimbra/log/audit.log for requests that create software passwords, notably entries named “ZimbraWeb.” The joint advisory additionally recommends revoking software passwords and 2FA scratch codes, resetting person passwords, and checking for indicators printed with the report.
Though Proofpoint states it couldn’t independently join TA488 to Void Blizzard with excessive confidence from its personal telemetry, collaboration with US authorities companions confirmed the affiliation. Proofpoint has not noticed exercise from the group since February 2026, however the advisory warns that weak Zimbra installations stay in danger.
(Photograph by Le Vu on Unsplash)









