A sophisticated Russian espionage group has been exploiting a vulnerability in Zimbra’s webmail client, allowing unauthorized access to Western email accounts. This security flaw, identified as CVE-2025-66376, had gone undetected for months, offering the attackers the ability to read communications and extract sensitive information such as email directories and two-factor authentication codes.
Exploiting the Zimbra Vulnerability
The espionage group targeted and compromised email systems using a stored cross-site scripting vulnerability in Zimbra’s Classic UI. This flaw allowed crafted HTML emails to execute JavaScript within authenticated sessions, giving attackers access to users’ email accounts without additional interaction. The vulnerability was actively used against Western government and commercial organizations from at least July 2025, as revealed by a joint advisory from the NSA, CISA, and other agencies.
Palo Alto Networks’ Unit 42 and Proofpoint provided detailed analyses of the campaign, highlighting how the attack required only viewing a malicious email to trigger the exploit. The attackers, tracked as TA488 by Proofpoint, utilized this vulnerability to infiltrate various sectors, including government, defense, and financial institutions across multiple regions.
Technical Details and Impact
The Zimbra flaw affected versions 10.0 before 10.0.18 and 10.1 before 10.1.13, with Zimbra releasing a patch on November 6, 2025. Despite this fix, compromised credentials remain a concern, as the patch does not revoke access already obtained through the exploit. The malicious payload, dubbed ZimReaper, was designed to steal CSRF tokens, browser-saved passwords, and two-factor authentication codes, exfiltrating data to attacker-controlled servers.
Unit 42 identified at least nine command-and-control (C2) servers used in the campaign, with each server remaining active for an average of 35.4 days. The exploit also involved embedding malicious code within email HTML content, which Zimbra’s sanitizer failed to detect as executable.
Mitigation and Ongoing Threats
Organizations are urged to upgrade Zimbra deployments to version 10.1.13 or later and to conduct thorough reviews of potentially compromised accounts. This includes resetting passwords, invalidating active sessions, and checking for signs of unauthorized access. Security researchers recommend using Proofpoint’s YARA rules to detect the exploit’s unique patterns in email HTML.
While Proofpoint noted a decline in activity from TA488 post-February 2026, the threat remains as attackers may continue targeting unpatched systems. The advisory emphasizes the importance of maintaining updated security measures to prevent further exploitation. Additionally, the ongoing assessment of the espionage group’s tactics underscores the need for vigilance and proactive cybersecurity strategies.
As organizations work to secure their systems, understanding the techniques and vulnerabilities exploited in this campaign is crucial for strengthening defenses against similar threats in the future.
