{"id":1980,"date":"2026-07-23T19:04:25","date_gmt":"2026-07-23T19:04:25","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1980"},"modified":"2026-07-23T19:04:25","modified_gmt":"2026-07-23T19:04:25","slug":"russian-espionage-group-exploited-zimbra-zero-day-to-steal-mail-and-2fa-codes","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1980","title":{"rendered":"Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjzlA3Ln3fk8yzrfLwR9egB99u67BL7NlRui9XkKviyXhFmZ3sYVTF5laSjHTwyphN51YvL39R0irNNPn2hDpVcn6EFi_NmuuSH3XTS9I71aPdZvgZRTOxXczmyqbSkcpqSy2TgOzSSJ0RzAyeQA4YXED73kIChZFtiuZ1fIVzCFvDJK4bEJ5M6Sj-qPeI\/s1700-e365\/zimbra-email.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra&#8217;s webmail client.<\/p>\n<p>The payload goes after the last 90 days of email, the organization&#8217;s entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening the message was enough to start it.<\/p>\n<p><a href=\"https:\/\/www.nsa.gov\/Press-Room\/Press-Releases-Statements\/Press-Release-View\/Article\/4553352\/nsa-and-partners-alert-zimbra-collaboration-suite-users-of-a-russian-state-supp\/\" target=\"_blank\">The NSA<\/a>, CISA and partner agencies published a <a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa26-204a\" target=\"_blank\">joint advisory<\/a> on the campaign Thursday, alongside research from Palo Alto Networks&#8217; Unit 42 and Proofpoint.<\/p>\n<p>The advisory calls the technique \u00aba view-based exploit that only requires a user to view a malicious email\u00bb in a vulnerable client. It says the actors have been targeting and compromising Western government and commercial organizations through Zimbra since at least July 2025.<\/p>\n<p>The flaw, <code>CVE-2025-66376<\/code>, is a stored cross-site scripting vulnerability in Zimbra&#8217;s Classic UI. A crafted HTML email abuses CSS <code>@import<\/code> handling to execute JavaScript inside an authenticated webmail session, so the payload inherits the user&#8217;s access to the mailbox.<\/p>\n<p>The two CVSS records disagree on whether viewing the message counts as user interaction: <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-66376\" target=\"_blank\">NVD scores it 6.1<\/a> and says it does; MITRE scores it 7.2 and says it does not. Unit 42 calls it zero-click. All three describe the same behavior: the message runs when it renders, and nothing else has to happen.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>It affects Zimbra Collaboration 10.0 before <code>10.0.18<\/code> and 10.1 before <code>10.1.13<\/code>. <a href=\"https:\/\/wiki.zimbra.com\/wiki\/Zimbra_Releases\/10.1.13\" target=\"_blank\">Zimbra fixed it<\/a> on November 6, 2025, and CISA <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-66376\" target=\"_blank\">added it to the Known Exploited Vulnerabilities catalog<\/a> on March 18, 2026. <a href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/ta488-targets-zimbra-mailservers-half-click-exploits\" target=\"_blank\">Proofpoint<\/a>, which tracks the actor as TA488, said the group exploited the bug as an unknown vulnerability for at least five months during 2025, before that fix existed.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The patch closes the hole, not the account. An update does not revoke credentials the payload already took.<\/p>\n<p>Proofpoint said the messages went out from adversary-controlled Proton Mail accounts and from previously compromised addresses, using generic lures. <a href=\"https:\/\/unit42.paloaltonetworks.com\/russian-webmail-espionage\/\" target=\"_blank\">Unit 42<\/a>, which tracks the activity as CL-STA-1114, said they were often dressed as a digest of current news. The exploit sits in the HTML body.<\/p>\n<p>It hides an <code>svg onload<\/code> tag inside a <code>display:none<\/code> div, then breaks the tag apart with fake <code>@import<\/code> directives and HTML comments, a technique Proofpoint calls tag-splitting. Zimbra&#8217;s sanitizer does not recognize the fragments as executable markup. It strips the <code>@import<\/code> sequences, and the characters left behind join into <code><svg onload=\"eval(atob(...))\"\/><\/code>, which the browser runs.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjWeIeXUk-7MFmxSMRqTtDjYCTFqBq7dE9Jl-NzTqDiLIsMv-EAzJitSzZrUHKwZozxWbS2hpvJ5NZf2Aj96wuQrUqvdeGFnfAaeHrELZriIP449-5oYrCO1lf2iNez1v-mVvI9dPVCW3VCyeOLqQzmtzYkuOGle1GAjbiptqEmgECvda1Ly15MilLR5Mw\/s1700-e365\/emails.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjWeIeXUk-7MFmxSMRqTtDjYCTFqBq7dE9Jl-NzTqDiLIsMv-EAzJitSzZrUHKwZozxWbS2hpvJ5NZf2Aj96wuQrUqvdeGFnfAaeHrELZriIP449-5oYrCO1lf2iNez1v-mVvI9dPVCW3VCyeOLqQzmtzYkuOGle1GAjbiptqEmgECvda1Ly15MilLR5Mw\/s1700-e365\/emails.png\" alt=\"\" border=\"0\" data-original-height=\"325\" data-original-width=\"803\"\/><\/a><\/div>\n<p>Proofpoint tracks the JavaScript payload as ZimReaper. It steals the CSRF token and the browser&#8217;s autofilled password, pulls 2FA scratch codes and Zimbra version details through the platform&#8217;s own APIs, and exfiltrates them over DNS queries to actor infrastructure. Then it brute-forces the Global Address List, querying every two-character combination until the whole list comes back, and posts 90 days of the victim&#8217;s mail to the C2 as a TGZ archive.<\/p>\n<p>Unit 42 counted at least nine C2 IP addresses and nine domains, each server live for an average of 35.4 days. It named no affected organizations and gave no victim count. Its list of sectors and regions describes who was targeted. It does not say who was compromised. That list runs across government, defense, transportation and financial organizations in NATO member states, Ukraine, the Commonwealth of Independent States and Africa. Proofpoint puts US organizations on it too: government, scientific and defense industrial base entities, including nuclear installations.<\/p>\n<p>The payload mints an app-specific password named <code>ZimbraWeb<\/code> through <code>CreateAppSpecificPasswordRequest<\/code>, which can grant IMAP, POP3 or SMTP access without two-factor authentication. Proofpoint said TA488 went on to send further exploit emails from compromised mailservers, and could not say whether the app passwords or other stolen credentials were what got it back in.<\/p>\n<p>In the January case <a href=\"https:\/\/www.seqrite.com\/blog\/operation-ghostmail-zimbra-xss-russian-apt-ukraine\/\" target=\"_blank\">Seqrite analyzed<\/a>, at a Ukrainian state hydrology agency, the payload also flipped <code>zimbraPrefImapEnabled<\/code> to TRUE. \u00abApp-specific passwords survive password resets,\u00bb the researchers wrote.<\/p>\n<h2>Patch, then check the accounts<\/h2>\n<p>Zimbra 10.0 <a href=\"https:\/\/blog.zimbra.com\/2025\/11\/patch-release-update-zimbra-10-1-13-10-0-18\/\" target=\"_blank\">reached end of life<\/a> on December 31, 2025, which makes <code>10.0.18<\/code> an emergency floor rather than a destination. The newest 10.1 release is <a href=\"https:\/\/wiki.zimbra.com\/wiki\/Zimbra_Releases\/10.1.20\" target=\"_blank\"><code>10.1.20<\/code><\/a>, out July 20, which fixes four more stored XSS flaws in the Classic Web Client.<\/p>\n<p>Upgrade 10.1 deployments to at least <code>10.1.13<\/code>, and move 10.0 deployments onto a supported 10.1 build. Then work the accounts. Any mailbox that opened or previewed a matching message in a vulnerable Classic UI session should be treated as potentially compromised: reset the password, invalidate active sessions, and regenerate 2FA scratch codes.<\/p>\n<p>Messages that landed but were never opened should be pulled and their HTML checked for the fragmented <code>@import<\/code> pattern, which Proofpoint&#8217;s published YARA rule matches. The update does none of the checks below.<\/p>\n<p>They come from Proofpoint&#8217;s and Seqrite&#8217;s guidance:<\/p>\n<ul>\n<li>Review <code>\/opt\/zimbra\/log\/audit.log<\/code> for calls to <code>CreateAppSpecificPassword<\/code> and remove any credential named <code>ZimbraWeb<\/code><\/li>\n<li>Find accounts with <code>zimbraPrefImapEnabled<\/code> set to TRUE that have no business need for IMAP<\/li>\n<li>Alert on SOAP calls to <code>GetScratchCodesRequest<\/code>, which should be close to absent in normal use<\/li>\n<li>Filter DNS for the <a href=\"https:\/\/unit42.paloaltonetworks.com\/russian-webmail-espionage\/\" target=\"_blank\">published C2 domains<\/a> and alert on the long random subdomain lookups the payload uses to exfiltrate<\/li>\n<\/ul>\n<h2>Still running?<\/h2>\n<p>How live the campaign is depends on whose telemetry you read. Unit 42 said threat actors continue to actively target unpatched ZCS instances using the flaw, without saying whether this cluster is among them.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thn.news\/sygnia-webinar\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjnP2BIJTKZ31v-Y_pyvFqC1s6LD-Bo8UNy3UHgqojpVezgaGWw5-sPe5uRK0dfSm3gmDvoKCdHoJnGx1BiTP6Y0qit7D7TCZU_LckTDpdu9eeyuelmJKndEkOxZP6oNPwzguLBCTkAnNkIEvSYaWamKLqYLrJPjnea1V_lz7UcfQkavBo2g3OEGoLyz7mD\/s728-e100\/sygnia-d-4.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The advisory warns of ongoing activity and assesses that the group will very likely keep going after Zimbra and other Western email systems, even if this campaign winds down as organizations patch. Proofpoint said it \u00abhas not observed any activity from TA488 since February 2026,\u00bb and tied the silence to Seqrite&#8217;s disclosure and the actor tearing down its own infrastructure. Neither vendor&#8217;s telemetry settles it.<\/p>\n<p>The Hacker News compared the two indicator lists and found the same nine domains in both, which puts Unit 42&#8217;s CL-STA-1114 and Proofpoint&#8217;s TA488 on the same infrastructure. Proofpoint&#8217;s first-seen dates run from July 2025 through February 2026.<\/p>\n<p>The advisory lists LAUNDRY BEAR, Void Blizzard, CL-STA-1114, and TA488 as names in community use for these actors, while cautioning that the mapping may not be one-to-one. Proofpoint said it could not tie TA488 to Void Blizzard from its own telemetry, and that US government partners confirmed the association. Seqrite attributed its January case to APT28 with medium confidence, while <a href=\"https:\/\/www.aivd.nl\/site\/binaries\/site-content\/collections\/documents\/2025\/05\/27\/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor\/Advisory%2BAIVD%2Ben%2BMIVD%2BPublic%2Breport%2Bon%2Bnew%2Bcyber%2Bactor.pdf\" target=\"_blank\">Dutch intelligence<\/a>, which named LAUNDRY BEAR, treats it and APT28 as separate actors.<\/p>\n<p>For defenders, the naming argument changes little. Patching stops the next crafted email from running. It does not revoke what the last one left behind, which is why the account review matters as much as the version number.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra&#8217;s webmail client. The payload goes after the last 90 days of email, the organization&#8217;s&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1981,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[439,2052,691,128,91,1723,54,571,126,750],"class_list":["post-1980","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-2fa","tag-codes","tag-espionage","tag-exploited","tag-group","tag-mail","tag-russian","tag-steal","tag-zeroday","tag-zimbra"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1980","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1980"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1980\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1981"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1980"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1980"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1980"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}