Russia-aligned hackers used Zimbra flaw in email attack
Wed, 29th Jul 2026 (Today)
Proofpoint said Russia-aligned threat actor TA488 used a previously unknown flaw in Zimbra mail servers to carry out a half-click email attack targeting Ukrainian government bodies and organisations in the United States.
The operation relied on a cross-site scripting vulnerability later tracked as CVE-2025-66376. The flaw was exploited for at least five months in 2025 before a patch was issued, allowing the attackers to steal emails and credentials and maintain access to affected Zimbra systems.
Proofpoint tracks the actor as TA488, previously identified as UNK_PitStop. The group is also known as Void Blizzard and Laundry Bear, and is likely directed by Russian intelligence.
The attacks centred on webmail servers, where malicious code embedded in an email body ran when a user opened or previewed the message in a vulnerable Zimbra webmail client. The method did not require a target to click a link, open an attachment or take any further action.
Researchers said the messages were sent from attacker-controlled Proton Mail accounts and previously compromised email addresses. The lures were described as generic, with one example referring to co-operation, data sharing and a meeting linked to a European Union setting.
How it worked
The vulnerability lay in Zimbra's client-side HTML sanitiser. TA488 exploited the way the software handled content between @import calls, enabling arbitrary JavaScript to run inside the victim's webmail session.
Once access was gained, the actor established persistence and exfiltrated emails from targeted users, according to the report. The campaign also sought credentials and enabled longer-term access to the mail server.
Proofpoint linked the activity to a broader pattern of Russian and Belarusian cyber espionage against webmail appliances over the past three years. Other groups documented by the threat intelligence community have used similar cross-site scripting weaknesses to target online email platforms.
Among the actors cited were TA422, also known as Sofacy, Forest Blizzard, Fancy Bear and APT28; TA473, known as WinterVivern; and TA445, known as Ghostwriter and UNC1151. Proofpoint said various clusters had used comparable methods to pillage webmail servers.
Targets
The Zimbra campaign targeted Ukrainian entities as well as government organisations, scientific institutions and defence industrial base organisations in the United States. It also referenced US nuclear installations as part of the targeting picture.
The disclosure came alongside separate findings that TA488 had launched a newer campaign against Outlook Web Access. In that activity, Proofpoint said simply opening an email in Outlook Web Access was enough to trigger the exploit.
That operation included what Proofpoint described as OWAReaper, a JavaScript implant designed to persist after browser restarts, credential changes and device reimaging. The campaign targeted government organisations in the US and Europe, along with telecoms, financial, hospitality and aerospace groups.
Infrastructure linked to that campaign dates back to March 2026, about two months before Microsoft's patch for CVE-2026-42897. Proofpoint said the timeline raised the possibility that the actor had access to a zero-day vulnerability.
The findings add to evidence that half-click attacks are becoming a notable technique in state-linked espionage because they reduce the need for visible social engineering. By relying on routine actions such as opening or previewing an email, the method can make detection harder for users and administrators.
For organisations running Zimbra, Proofpoint advised reviewing audit logs for calls to 'Create App Specific Password' and remediating any named ZimbraWeb, or similar. It said TA488 is one of several Russian-aligned groups it tracks using half-click exploits to target email servers.