A Russian state-backed espionage group used CVE-2025-66376 in Zimbraβs Classic UI to read Western mailboxes for months, stealing recent email, directories, saved passwords, and 2FA recovery codes. The campaign, tracked as TA488 and CL-STA-1114, used crafted HTML emails with the ZimReaper payload and targeted government, defense, transportation, financial, and US organizations before Zimbraβs November 2025 patch. #CVE-2025-66376 #Zimbra #ZimReaper #TA488 #CL-STA-1114 #LAUNDRYBEAR #VoidBlizzard #APT28
Keypoints
- CVE-2025-66376 is a stored XSS flaw in Zimbra Classic UI.
- Opening a malicious email was enough to trigger code execution.
- The ZimReaper payload stole mail, passwords, CSRF tokens, and 2FA scratch codes.
- Attackers used app-specific passwords and DNS exfiltration to keep access.
- Defenders should patch Zimbra and review accounts for compromise signs.
Read More: https://thehackernews.com/2026/07/russian-espionage-group-exploited.html