Russian Hackers Used a Zimbra Zero-Day to Steal Emails Without Link Clicks
ID: b68a06bd-28da-539b-ba75-909bccaa9491
STIX ID: report--b68a06bd-28da-539b-ba75-909bccaa9491
Feed Name: HackRead
Proofpoint and US government partners attribute a campaign to Russia-linked TA488 that exploited a Zimbra zero-day (CVE-2025-66376) allowing malicious JavaScript in an email's HTML body to run on preview; the attacker-deployed ZimReaper harvested email addresses, browser-saved passwords, 2FA scratch codes, exported up to 90 days of mail, created persistent "ZimbraWeb" application passwords, and exfiltrated data via DNS and web traffic. Zimbra released patches in November 2025 (ZCS 10.1.13 and 10.0.18) and the advisory urges administrators to update servers, revoke application passwords and 2FA scratch codes, reset passwords, and review audit logs for signs of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
