TA488 Targets Zimbra Mailservers with Half-Click Exploits

TA488 Targets Zimbra Mailservers with Half-Click Exploits
Proofpoint reports that TA488, also tracked as Void Blizzard and Laundry Bear, exploited CVE-2025-66376 in Zimbra mailservers for months to gain persistent access and steal emails from targeted users. The campaigns used half-click HTML/XSS payloads, DNS-based exfiltration, and a malware family Proofpoint calls ZimReaper to target Ukrainian government entities and U.S. government, science, and defense organizations. #TA488 #VoidBlizzard #LaundryBear #CVE-2025-66376 #Zimbra #ZimReaper

Keypoints

  • TA488 exploited a previously unknown Zimbra vulnerability, CVE-2025-66376, for at least five months during 2025 before it was patched.
  • The actor used half-click attacks, where simply opening the email in Zimbra Webmail triggered the exploit without additional user interaction.
  • Targeting focused on Ukrainian government entities and U.S. government, high-science, nuclear, and defense industrial base organizations.
  • After exploitation, the malware established persistence, stole emails, gathered credentials and 2FA data, and enabled continued access to compromised mailboxes.
  • Proofpoint named the malware family ZimReaper and described its use of DNS exfiltration, app-specific passwords, and browser-based JavaScript execution.
  • The actor also abused compromised accounts to send follow-on phishing emails, increasing the legitimacy of subsequent lures.
  • Infrastructure used spoofed Zimbra- and email-analytics-themed domains, often behind Cloudflare nameservers, to mask command-and-control traffic.

MITRE Techniques

  • [T1059.007] JavaScript – Used to run malicious code in the victim’s browser after the email was opened (‘the browser successfully reconstructs and executes it’)
  • [T1189] Drive-by Compromise – The exploit triggered when the victim opened or previewed the email in Zimbra Webmail (‘fires as soon as the victim opens or previews it’)
  • [T1055] Process Injection – Not mentioned.
  • [T1027] Obfuscated Files or Information – Payloads were hidden with tag-splitting, @import fragmentation, Base32 encoding, and XOR wrapping (‘fragmenting it with fake CSS @import directives’, ‘wrapped its final payload in a basic XOR loop’)
  • [T1114.001] Local Email Collection – The actor iterated over and exfiltrated emails from the victim mailbox (‘iterates over the last 90 days’ worth of emails accessible to the targeted user’)
  • [T1113] Screen Capture – Not mentioned.
  • [T1114.003] Email Collection – Emails were stolen from targeted Zimbra accounts and sent to C2 via HTTP POST/TGZ (‘exfiltrate those messages via an HTTP POST request in a TGZ file’)
  • [T1005] Data from Local System – The script stole stored browser/mail data including CSRF token, auto-complete password, and 2FA codes (‘steals the Cross-Site Request Forgery (CSRF) token and the auto-complete password’)
  • [T1217] Browser Session Hijacking – The JavaScript operated inside the authenticated webmail session to access all available data (‘grants access to all data available inside of the authenticated webmail session’)
  • [T1071.004] DNS – The malware exfiltrated data through DNS queries to adversary infrastructure (‘exfiltrated via DNS query’)
  • [T1090] Proxy – Not mentioned.
  • [T1136.003] Create Account: Email Account – The actor created an app-specific password for persistent access (‘set up an app-specific password under the name “ZimbraWeb”’)
  • [T1556.006] Modify Authentication Process: Network Device Authentication – Not mentioned.
  • [T1041] Exfiltration Over C2 Channel – Data was sent back to the C2 via DNS and HTTP requests (‘exfiltrated alongside the victim’s email address’)
  • [T1590] Gather Victim Network Information – The script queried Zimbra version, server URL, and installation details (‘information about the Zimbra installation’)
  • [T1087.001] Account Discovery: Local Account – Not mentioned.
  • [T1087.004] Domain Account Discovery – The malware walked the Global Address List to enumerate contacts (‘walk the Global Address List using queries with every possible two-character combination’)
  • [T1566.001] Spearphishing Attachment – Not mentioned.
  • [T1566.002] Spearphishing Link – Not mentioned.
  • [T1566] Phishing – The actor sent exploit-laden emails from adversary-controlled and compromised accounts (‘messages exploiting CVE-2025-66376 from both adversary-controlled Proton Mail accounts and previously compromised addresses’)

Indicators of Compromise

  • [Domains] ZimReaper C2 / spoofed Zimbra telemetry domains – zmailanalytics[.]com, zimbra-metadata[.]com, and 6 more domains
  • [Email addresses] Actor-controlled sender accounts – c.laurent.ejfa@proton[.]me, j.moreau.epsc@proton[.]me, and liberty.insights@proton[.]me
  • [SHA256 hashes] Exploit emails used in campaigns – 98df604ecc57f884a2e6ce3266a0013ad64455cac48442c2312cfa4765007aaf, 60db9abae75cd8ccc49dd7ea5feb41677566dcd442f12ebc5745ffd2810fb874, and 2 more hashes
  • [File name / script identifier] Embedded JavaScript identifier seen in payloads – zmb_pl_v3_
  • [CVE] Vulnerability exploited in Zimbra Webmail – CVE-2025-66376
  • [Rule / detection content] YARA rule for tracking TA488 exploit emails – TA488_Zimbra_Exploit_Email


Read more: https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits