Updated
Updated · proofpoint.com · Jul 23
TA488 Exploited Zimbra Flaw CVE-2025-66376 for 5 Months to Steal Government Credentials
Updated
Updated · proofpoint.com · Jul 23

TA488 Exploited Zimbra Flaw CVE-2025-66376 for 5 Months to Steal Government Credentials

3 articles · Updated · proofpoint.com · Jul 23

Summary

  • Proofpoint said TA488 abused the previously unknown Zimbra bug for at least five months in 2025, targeting Ukrainian government bodies and U.S. government, science and defense-industrial entities before the flaw was patched.
  • The half-click attack required only opening or previewing an email in vulnerable Zimbra webmail, where embedded HTML triggered JavaScript without any link click or attachment opening.
  • ZimReaper malware then stole CSRF tokens, autofill passwords and 2FA data, created a persistent app-specific password called "ZimbraWeb," and exfiltrated the last 90 days of email plus directory data.
  • Proofpoint said TA488 also reused compromised accounts to send more exploit emails and spoofed Zimbra telemetry domains for command-and-control, with infrastructure active until February 2026.
  • The researchers linked TA488 to Void Blizzard, saying U.S. government partners confirmed the Russia-intelligence association; they advised Zimbra users to check audit logs for CreateAppSpecificPassword entries.

Insights

Could your enterprise webmail still harbor undetected persistence mechanisms left behind by the 2025 ZimReaper espionage campaign?
How did a simple email preview allow hackers to silently bypass two-factor authentication and steal months of classified data?
If clicking a link is no longer required to trigger an attack, is any web-based inbox truly safe from nation-state hackers?

Inside the TA488 Zimbra Attacks: Technical Analysis, Global Impact, and Incident Response for the 2025–2026 Zero-Day Campaign

Overview

The TA488 threat group exploited a critical Zimbra vulnerability by sending malicious emails that abused CSS @import directives. When users opened these emails in the Classic UI, scripts executed automatically, allowing attackers to deploy the ZimReaper payload. ZimReaper harvested sensitive data and created app-specific passwords, granting persistent access that bypassed two-factor authentication and survived password resets. Even after emergency patches closed the initial vulnerability, organizations running unsupported Zimbra versions remained at risk. This campaign highlights how a single email can lead to long-term compromise, emphasizing the need for both patching and thorough post-incident remediation.

...