logo

Russian Hackers Used a Zimbra Zero-Day to Steal Emails Without Link Clicks

ID: b68a06bd-28da-539b-ba75-909bccaa9491

STIX ID: report--b68a06bd-28da-539b-ba75-909bccaa9491

Feed Name: HackRead

Threat Score
90/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

Author: Waqas

...
...

Proofpoint and US government partners attribute a campaign to Russia-linked TA488 that exploited a Zimbra zero-day (CVE-2025-66376) allowing malicious JavaScript in an email's HTML body to run on preview; the attacker-deployed ZimReaper harvested email addresses, browser-saved passwords, 2FA scratch codes, exported up to 90 days of mail, created persistent "ZimbraWeb" application passwords, and exfiltrated data via DNS and web traffic. Zimbra released patches in November 2025 (ZCS 10.1.13 and 10.0.18) and the advisory urges administrators to update servers, revoke application passwords and 2FA scratch codes, reset passwords, and review audit logs for signs of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.