A Russian state-sponsored espionage group exploited a zero-day vulnerability in Zimbra’s webmail client to steal emails, passwords, and two-factor authentication recovery codes from Western government and commercial organizations. The flaw, CVE-2025-66376, is a stored cross-site scripting vulnerability in Zimbra’s Classic UI that allows a crafted HTML email to execute JavaScript within an authenticated webmail session upon viewing.
The campaign, active since at least July 2025, targeted organizations in NATO member states, Ukraine, the Commonwealth of Independent States, Africa, and the United States, including government, defense, transportation, financial, and nuclear installations. The exploit, tracked as ZimReaper by Proofpoint, steals CSRF tokens, autofilled passwords, 2FA scratch codes, and exfiltrates 90 days of email via DNS queries. It also creates an app-specific password named ‘ZimbraWeb’ that bypasses two-factor authentication.
Zimbra fixed the vulnerability on November 6, 2025, with patches for versions 10.0.18 and 10.1.13. CISA added it to the Known Exploited Vulnerabilities catalog on March 18, 2026. The advisory, jointly published by the NSA, CISA, Palo Alto Networks’ Unit 42, and Proofpoint, warns of ongoing activity and recommends patching and account review to mitigate compromise.
CVEs: CVE-2025-66376
Attack groups: TA488, CL-STA-1114, LAUNDRY BEAR, Void Blizzard, APT28
Malware: ZimReaper
Companies: Palo Alto Networks, Proofpoint, Seqrite
Products: Zimbra Collaboration
Original source: thehackernews.com