Russian Hackers Used a Zimbra Zero-Day to Steal Emails Without Link Clicks

https://hackread.com/wp-content/uploads/2026/07/russian-hackers-zimbra-0-day-steal-emails-link-clicks.jpg

Opening or previewing a malicious email was enough for Russian-linked hackers to compromise users of vulnerable Zimbra webmail servers. The campaign required no link click or attachment download, allowing the exploit to run as soon as the message appeared in the webmail client.

Proofpoint attributes the activity to TA488, a Russia-aligned espionage group also tracked as Laundry Bear and Void Blizzard. The company released its findings in coordination with reporting from the NSA and FBI’s JSAC, while a joint government advisory described the group as state-supported and focused on collecting information for Russia.

According to the advisory (PDF), the group targets included Ukrainian government bodies, US government and defense organizations, nuclear installations, scientific institutions and entities in Europe. Proofpoint said the actor had used the previously unknown Zimbra vulnerability since at least July 2025, at least five months before public disclosure.

Opening an Email Triggers the Attack

When a recipient...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE

Read more