Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported espionage group exploited a zero-day vulnerability in Zimbra's webmail client to steal mail and 2FA codes. The group targeted Western government and commercial organizations through Zimbra since at least July 2025.
Intelligence analysis by Llama

A Russian espionage group exploited a zero-day vulnerability in Zimbra's webmail client to steal mail and 2FA codes. The group targeted Western government and commercial organizations through Zimbra since at least July 2025. The vulnerability, CVE-2025-66376, is a stored cross-site scripting vulnerability in Zimbra's Classic UI.
Imagine you're using a special email client called Zimbra. A group of hackers found a way to sneak into Zimbra's system and steal your email and 2FA codes. They did this by sending you a fake email that looked like a normal email, but had some secret code inside it. When you opened the email, the code ran and stole your information. This is a big security issue because it shows how vulnerable our email systems can be to hacking.
Analysis
A Zero-Day Vulnerability in Zimbra's Webmail Client
A Russian state-supported espionage group has been exploiting a zero-day vulnerability in Zimbra's webmail client to steal mail and 2FA codes. The group targeted Western government and commercial organizations through Zimbra since at least July 2025. The vulnerability, CVE-2025-66376, is a stored cross-site scripting vulnerability in Zimbra's Classic UI.
The exploit sits in the HTML body of the email and hides an svg onload tag inside a display:none div. It breaks the tag apart with fake @import directives and HTML comments, a technique Proofpoint calls tag-splitting. Zimbra's sanitizer does not recognize the fragments as executable markup, allowing the browser to run the JavaScript payload.
The payload, tracked by Proofpoint as ZimReaper, steals the CSRF token and the browser's autofilled password, pulls 2FA scratch codes and Zimbra version details through the platform's own APIs, and exfiltrates them over DNS queries to actor infrastructure. It then brute-forces the Global Address List, querying every two-character combination until the whole list comes back, and posts 90 days of the victim's mail to the C2 as a TGZ archive.
The advisory warns of ongoing activity and assesses that the group will very likely keep going after Zimbra and other Western email systems, even if this campaign winds down. The importance of timely patching and security updates to prevent such attacks cannot be overstated.
Key points
- A Russian state-supported espionage group exploited a zero-day vulnerability in Zimbra's webmail client to steal mail and 2FA codes.
- The group targeted Western government and commercial organizations through Zimbra since at least July 2025.
- The vulnerability, CVE-2025-66376, is a stored cross-site scripting vulnerability in Zimbra's Classic UI.
- The exploit sits in the HTML body of the email and hides an svg onload tag inside a display:none div.
- The payload, tracked by Proofpoint as ZimReaper, steals the CSRF token and the browser's autofilled password, pulls 2FA scratch codes and Zimbra version details through the platform's own APIs, and exfiltrates them over DNS queries to actor infrastructure.
The good news is that Zimbra has already fixed the vulnerability, and users can update to the latest version to prevent further attacks. Additionally, the advisory warns of ongoing activity, but it also highlights the importance of timely patching and security updates to prevent such attacks.
The bad news is that the group will likely continue to target unpatched ZCS instances using the flaw, and the advisory warns of ongoing activity. This highlights the ongoing threat of state-sponsored espionage groups targeting Western organizations through vulnerabilities in email systems.



