Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
Zimbra is an email and collaboration platform used by governments and businesses worldwide. For at least five months in 2025, a Russian state-backed espionage group — tracked as TA488 by Proofpoint and CL-STA-1114 by Palo Alto Networks' Unit 42 — read Western mailboxes through a then-unknown flaw in Zimbra's webmail client, according to a joint advisory from the NSA, CISA, and partner agencies.
The flaw, CVE-2025-66376, is a stored cross-site scripting (XSS) vulnerability — a technique where attackers inject malicious code into a webpage that then runs inside another user's browser session. In this case, attackers sent crafted HTML emails that executed JavaScript the moment the message rendered. The victim did not need to click anything. Unit 42 calls this zero-click (requiring no interaction from the target whatsoever).
Once triggered, a payload called ZimReaper went to work silently. It stole saved passwords, two-factor recovery codes, and 90 days of the victim's emails, then packaged and sent the whole archive to attacker-controlled servers. It also created an app-specific password inside Zimbra, granting the attackers persistent email access without triggering two-factor prompts.
Targets spanned government, defence, transportation, and financial organisations in NATO member states, Ukraine, and the US — including nuclear installations.
Zimbra patched the flaw on 6 November 2025. CISA added it to its Known Exploited Vulnerabilities catalogue in March 2026.
What you should do: If your organisation uses Zimbra Collaboration, verify you are running version 10.0.18 or 10.1.13 or later. Patching closes the hole — but it does not undo any access already gained. Check for unexpected app-specific passwords inside Zimbra settings and rotate credentials for any account that may have been exposed.
Sources

