Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-backed espionage group used CVE-2025-66376 in Zimbra’s Classic UI to read Western mailboxes for months, stealing recent email, directories, saved passwords, and 2FA recovery codes. The campaign, tracked as TA488 and CL-STA-1114, used crafted HTML emails with the ZimReaper payload and targeted government, defense, transportation, financial, and US organizations before Zimbra’s November 2025 patch. #CVE-2025-66376 #Zimbra #ZimReaper #TA488 #CL-STA-1114 #LAUNDRYBEAR #VoidBlizzard #APT28

Keypoints

  • CVE-2025-66376 is a stored XSS flaw in Zimbra Classic UI.
  • Opening a malicious email was enough to trigger code execution.
  • The ZimReaper payload stole mail, passwords, CSRF tokens, and 2FA scratch codes.
  • Attackers used app-specific passwords and DNS exfiltration to keep access.
  • Defenders should patch Zimbra and review accounts for compromise signs.

Read More: https://thehackernews.com/2026/07/russian-espionage-group-exploited.html