How a Russian Spy Group Exploited a Zimbra Zero-Day to Harvest Emails and 2FA Credentials

Overview of the Zimbra Zero-Day Exploit

In mid-2025 a Russian state-backed espionage group began leveraging a previously unknown flaw in the Zimbra Collaboration Suite (ZCS). The vulnerability, cataloged as CVE-2025-66376, is a stored cross-site scripting (XSS) issue in the Classic UI. Because the attack is triggered simply by opening a malicious email, it is classified as a zero-click or view-based exploit.

Technical Mechanics of the Attack

The malicious payload is embedded in crafted HTML messages that abuse the CSS @import directive. When a victim views the email in a logged-in Zimbra webmail session, the hidden JavaScript runs with the same privileges as the authenticated user. This allows the script to:

  • Read the last 90 days of email messages.
  • Download the entire Global Address List (GAL) of the organization.
  • Extract browser-saved passwords and two-factor authentication (2FA) recovery codes.
  • Collect CSRF tokens, system details, and other session data.
  • Transmit the stolen information to attacker-controlled servers via DNS queries.

Timeline and Mitigation Efforts

The campaign was active for roughly five months before Zimbra released an official patch on 6 November 2025. Despite the fix, unpatched installations continue to be targeted. On 18 March 2026 the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-66376 to its Known Exploited Vulnerabilities catalog, highlighting the ongoing risk.

Targets and Impact

Primary victims include Western government agencies and commercial enterprises, with a notable focus on Ukrainian organizations that serve as a testing ground for new techniques. Affected sectors span defense, education, energy, law enforcement, media, finance, transportation, and technology. The exfiltrated data gives the adversary a comprehensive view of internal communications and credential stores, enabling further intrusion and lateral movement.

‘The patch closes the vulnerability but does not revoke credentials that may already be compromised,’ statement from the joint advisory issued by the NSA, CISA, Palo Alto Networks Unit 42, and Proofpoint.

Recommended Defensive Measures

Organizations using Zimbra should apply the November 2025 security update immediately. Additional steps include:

  • Force password resets for accounts that accessed Zimbra before the patch.
  • Invalidate and re-issue all 2FA recovery codes.
  • Monitor DNS traffic for anomalous queries to known malicious domains.
  • Deploy web application firewalls that can detect and block unexpected @import calls.
  • Conduct regular audits of the Global Address List and email logs for unauthorized access.

Conclusion

The Zimbra zero-day campaign demonstrates how a seemingly minor XSS flaw can be weaponized into a large-scale espionage operation. By exploiting the view-based nature of the bug, the Russian group achieved silent, credential-stealing access to high-value targets across multiple industries. Prompt patching, credential rotation, and network monitoring remain essential to mitigate the lingering threat.

Share:

LinkedIn

Share
Copy link
URL has been copied successfully!


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Close filters
Products Search