This Russian cybercrime campaign can infect a user just by viewing an email
- Proofpoint reports Russian TA488 exploited Zimbra zero‑day CVE‑2025‑66376 in espionage campaigns
- “Half‑click exploit” let attackers compromise systems when victims merely viewed malicious emails
- Targets included NATO, Ukrainian government, and defense entities; group vanished after Feb 2026 exposure
Russian state-sponsored cybercriminals have been abusing a zero-day vulnerability in the Zimbra email and collaboration platform to conduct espionage against western targets - primarily military and government agencies, experts have warned.
Cybersecurity researchers Proofpoint claim the campaign has been ongoing for at least a year, possibly longer, describing it as a “half-click exploit”, because the victims don’t even need to do anything specific in order to get infected.
Usually, when an attack is done via email, the victim is required to at least download a file or click a link. In this case, a cross-site scripting (XSS) vulnerability in the Zimbra web-based email service allowed the Russians to infiltrate the computers as soon...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE