CyberSecurityBoardThreat Intel · CVEs · Products
Attack Groups

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

July 23, 2026

A Russian state-sponsored espionage group exploited a zero-day vulnerability in Zimbra’s webmail client to steal emails, passwords, and two-factor authentication recovery codes from Western government and commercial organizations. The flaw, CVE-2025-66376, is a stored cross-site scripting vulnerability in Zimbra’s Classic UI that allows a crafted HTML email to execute JavaScript within an authenticated webmail session upon viewing.

The campaign, active since at least July 2025, targeted organizations in NATO member states, Ukraine, the Commonwealth of Independent States, Africa, and the United States, including government, defense, transportation, financial, and nuclear installations. The exploit, tracked as ZimReaper by Proofpoint, steals CSRF tokens, autofilled passwords, 2FA scratch codes, and exfiltrates 90 days of email via DNS queries. It also creates an app-specific password named ‘ZimbraWeb’ that bypasses two-factor authentication.

Zimbra fixed the vulnerability on November 6, 2025, with patches for versions 10.0.18 and 10.1.13. CISA added it to the Known Exploited Vulnerabilities catalog on March 18, 2026. The advisory, jointly published by the NSA, CISA, Palo Alto Networks’ Unit 42, and Proofpoint, warns of ongoing activity and recommends patching and account review to mitigate compromise.

CVEs: CVE-2025-66376

Attack groups: TA488, CL-STA-1114, LAUNDRY BEAR, Void Blizzard, APT28

Malware: ZimReaper

Companies: Palo Alto Networks, Proofpoint, Seqrite

Products: Zimbra Collaboration