Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
AI Generated Image

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

The Hacker News world

Key Points:

  • A Russian state-supported espionage group exploited a zero-click stored cross-site scripting vulnerability (CVE-2025-66376) in Zimbra's Classic Webmail Client to steal emails, passwords, and two-factor recovery codes from Western government and commercial organizations since at least July 2025.
  • The exploit, delivered via crafted HTML emails, executes JavaScript upon message rendering without user interaction, allowing attackers to exfiltrate 90 days of emails, address book data, and credentials through DNS queries to their infrastructure.
  • Zimbra patched the vulnerability in November 2025, but compromised credentials and app-specific passwords remain valid, requiring organizations to reset passwords, invalidate sessions, and regenerate 2FA codes to fully remediate.
  • The campaign targeted sectors including government, defense, transportation, and finance across NATO countries, Ukraine, CIS states, Africa, and the US, with threat actors using compromised Proton Mail accounts and previously breached addresses to send malicious emails.
  • Security agencies warn that while active exploitation may have decreased since early 2026, unpatched systems remain at risk, emphasizing the importance of upgrading Zimbra to at least version 10.1.13 and auditing affected accounts for signs of compromise.

Trending Business

Trending Technology

Trending Health