A Russian espionage group has reportedly exploited a zero-day vulnerability in the Zimbra Collaboration webmail client to steal sensitive user data, including emails and two-factor authentication codes. The campaign, attributed to the group TA488 (also known as LAUNDRY BEAR or Void Blizzard), began as early as July 2025 and continued for several months until the vulnerability was patched in November 2025.
The vulnerability, identified as CVE-2025-66376, allowed attackers to compromise user accounts through a seemingly simple interaction. Users merely viewing a specially crafted HTML email were susceptible to the exploit. This mechanism suggests a client-side vulnerability, likely involving improper handling of HTML content or embedded scripts within the webmail interface.
Once triggered, the exploit enabled the attackers to exfiltrate a range of sensitive information. This included not only the contents of emails and contact lists but also browser-saved passwords and two-factor authentication (2FA) codes. The ability to steal 2FA codes is particularly concerning, as it bypasses a critical layer of security designed to protect accounts even if primary credentials are compromised.
Zimbra Collaboration is a widely used open-source email and collaboration suite, deployed by organizations of various sizes. Its extensive feature set, including email, calendaring, and document sharing, makes it a valuable target for espionage groups seeking access to organizational communications and data. The impact of such a vulnerability could extend to any organization utilizing the affected versions of the Zimbra webmail client during the exploitation window.
Mitigation for this class of vulnerability typically involves prompt patching of affected software. In this instance, Zimbra released a patch in November 2025 to address CVE-2025-66376. Organizations using Zimbra Collaboration are advised to ensure their installations are fully updated to the latest secure versions. Additionally, users should be cautious about opening suspicious emails, even though in this specific case, merely viewing the email was sufficient for exploitation.
This incident highlights the persistent threat posed by sophisticated state-sponsored groups targeting widely used enterprise software. The exploitation of zero-day vulnerabilities, before vendors can release patches, underscores the challenge in defending against advanced persistent threats. It also reinforces the importance of layered security approaches and continuous monitoring for unusual activity within email and collaboration platforms.






