Russian TA488 Exploits Zimbra CVE-2025-66376 to Target Government Mail Servers  | eSecurity Planet

Russian TA488 Exploits Zimbra CVE-2025-66376 to Target Government Mail Servers 

Russian-aligned TA488 exploited Zimbra CVE-2025-66376 in a half-click attack.

Written By
Ken Underhill
Ken Underhill
Jul 23, 2026
4 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Russian-aligned TA488 exploited Zimbra flaw CVE-2025-66376 for at least five months using a half-click attack triggered when victims opened or previewed a malicious email. 

The campaign targeted Ukrainian and U.S. government, defense, and scientific organizations, allowing attackers to steal sensitive emails and maintain persistent access to compromised mail servers. 

“What’s interesting here is that more than a year later, attackers are still finding success with what is now a well-known vulnerability,” said Steve Povolny, VP of AI Strategy & Security Research at Exabeam, in an email to eSecurityPlanet.

He explained, “A zero-day has a limited shelf life, but poor patch hygiene can extend its usefulness indefinitely.”

Ross Filipek, CISO at Corsica Technologies added, “Viewing a malicious email in a vulnerable Zimbra environment was enough to trigger the exploit. That negates the warning signs most security training is built around.”

Key takeaways of the TA488 Zimbra attack campaign

  • Russian-aligned TA488 exploited a Zimbra vulnerability, CVE-2025-66376, for at least five months using a browser-based half-click attack.
  • Simply opening or previewing a malicious email allowed attackers to execute JavaScript without requiring victims to click links or open attachments.
  • The ZimReaper malware harvested credentials, established persistent mailbox access, and exfiltrated approximately 90 days of email data.
  • The campaign targeted Ukrainian and U.S. government, defense, and scientific organizations while using compromised mailboxes to expand attacks.
  • Organizations should prioritize patching Zimbra, continuous mail server monitoring, and Zero Trust controls to limit blast radius.

How the TA488 Zimbra attack worked 

Unlike traditional phishing, TA488’s half-click exploit triggered when victims opened or previewed a malicious email in a vulnerable Zimbra client.

Once the email was viewed, attacker-controlled JavaScript executed automatically within the user’s authenticated browser session, giving the attackers access without any additional user interaction.

Proofpoint said TA488 — also tracked as Void Blizzard and Laundry Bear — primarily targeted Ukrainian government organizations, along with U.S. government, defense, and scientific organizations. 

The attackers delivered exploit-laden emails from both compromised accounts and attacker-controlled Proton Mail addresses, increasing the likelihood that messages would appear legitimate to recipients.

Advertisement

How CVE-2025-66376 enabled browser-based compromise 

The campaign exploited CVE-2025-66376, a cross-site scripting (XSS) vulnerability in Zimbra’s client-side HTML sanitizer. 

TA488 embedded malicious HTML directly within email messages and disguised the payload using techniques such as HTML tag splitting, fake CSS @import directives, and HTML comments. 

While Zimbra’s sanitizer failed to recognize the fragmented code as malicious, the victim’s browser reconstructed the HTML into executable JavaScript, allowing the payload to run automatically. 

Beginning in October 2025, the group further improved its ability to evade detection by encrypting the final JavaScript payload with campaign-specific XOR keys before execution.

How ZimReaper established persistence and stole data 

Proofpoint tracks the malware used in the campaign as ZimReaper. 

After executing within the authenticated browser session, the malware harvested cross-site request forgery (CSRF) tokens, browser-stored passwords, two-factor authentication recovery codes, email addresses, and Zimbra server information. 

It also created an application-specific password named “ZimbraWeb,” providing persistent IMAP, POP3, and SMTP access that bypassed multi-factor authentication. 

Beyond credential theft, ZimReaper enumerated organizational contacts, exported approximately 90 days of accessible email, and exfiltrated stolen data using DNS tunneling and HTTP POST requests.

Proofpoint also observed TA488 leveraging compromised mailboxes to distribute additional exploit emails to new targets. 

By sending malicious messages from trusted accounts inside victim organizations, the group increased the credibility of its spear-phishing campaigns while expanding access across government and enterprise networks.

Advertisement

How organizations can reduce risk from Zimbra attacks 

Because TA488 combined browser-based exploitation, credential theft, persistence, and data exfiltration, defending against these campaigns requires both patching and continuous monitoring of mail server activity. 

  • Patch all Zimbra servers to the latest version, and disable or closely monitor application-specific passwords for unauthorized entries such as unexpected “ZimbraWeb” accounts. 
  • Monitor Zimbra API activity, mailbox exports, authentication events, and large email downloads for signs of unauthorized access.
  • Inspect outbound DNS traffic for tunneling activity and other unusual queries that could indicate data exfiltration.
  • Strengthen email security by detecting obfuscated HTML content and applying the latest webmail protections and security updates.
  • Apply least-privilege access controls, continuously monitor privileged accounts, and centralize mail server and authentication logs for threat detection.
  • Test incident response plans with attack simulation tools and scenarios around browser-based attacks, credential theft, and webmail compromise.

These measures can help organizations strengthen detection, limit attacker persistence, and improve overall incident response. 

Bottom line

Webmail platforms remain attractive targets for nation-state actors because they provide direct access to sensitive communications, credentials, and trusted identities. 

Organizations should ensure their email security strategy extends beyond just phishing prevention to include continuous monitoring, vulnerability remediation, and controls designed to detect post-compromise activity. 

These campaigns reinforce why Zero Trust has become a foundational security strategy for limiting the impact of compromised identities and enterprise applications. 

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.