Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes 14%

By Swati Khandelwal11%

7/23/2026, 6:36:08 PM

BS Summary: This article contains 25 faulty reasoning types, including Negativity Bias, Ambiguity (Equivocation), and Appeal to Authority, with Overconfidence Bias as the most egregious example at 19.6% saturation with 214 hits. Analysis detected 984 faulty-reasoning hits from 1,090 analyzed words, generating a BS Score of 30.4% and a BS Rank of 14% (18,912 of 21,887 articles). This article is better (less manipulative) than 86.40% of the article peer group.

A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. 
The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the codes kept for two-factor recovery. 
Opening the message was enough to start it. 
The NSA, CISA and partner agencies published a joint advisory on the campaign Thursday, alongside research from Palo Alto Networks' Unit 42 and Proofpoint. 
The advisory calls the technique "a view-based exploit that only requires a user to view a malicious email" in a vulnerable client. 
It says the actors have been targeting and compromising Western government and commercial organizations through Zimbra since at least July 2025. 
The flaw, CVE-2025-66376, is a stored cross-site scripting vulnerability in Zimbra's Classic UI. 
A crafted HTML email abuses CSS @import handling to execute JavaScript inside an authenticated webmail session, so the payload inherits the user's access to the mailbox. 
The two CVSS records disagree on whether viewing the message counts as user interaction: NVD scores it 6.1 and says it does; MITRE scores it 7.2 and says it does not. 
Unit 42 calls it zero-click. 
All three describe the same behavior: the message runs when it renders, and nothing else has to happen. 
It affects Zimbra Collaboration 10.0 before 10.0.18 and 10.1 before 10.1.13. 
Zimbra fixed it on November 6, 2025, and CISA added it to the Known Exploited Vulnerabilities catalog on March 18, 2026. 
Proofpoint, which tracks the actor as TA488, said the group exploited the bug as an unknown vulnerability for at least five months during 2025, before that fix existed. 
The patch closes the hole, not the account. 
An update does not revoke credentials the payload already took. 
Proofpoint said the messages went out from adversary-controlled Proton Mail accounts and from previously compromised addresses, using generic lures. 
Unit 42, which tracks the activity as CL-STA-1114, said they were often dressed as a digest of current news. 
The exploit sits in the HTML body. 
It hides an svg onload tag inside a display:none div, then breaks the tag apart with fake @import directives and HTML comments, a technique Proofpoint calls tag-splitting. 
Zimbra's sanitizer does not recognize the fragments as executable markup. 
It strips the @import sequences, and the characters left behind join into <svg onload=eval(atob(...))>, which the browser runs. 
Proofpoint tracks the JavaScript payload as ZimReaper. 
It steals the CSRF token and the browser's autofilled password, pulls 2FA scratch codes and Zimbra version details through the platform's own APIs, and exfiltrates them over DNS queries to actor infrastructure. 
Then it brute-forces the Global Address List, querying every two-character combination until the whole list comes back, and posts 90 days of the victim's mail to the C2 as a TGZ archive. 
Unit 42 counted at least nine C2 IP addresses and nine domains, each server live for an average of 35.4 days. 
It named no affected organizations and gave no victim count. 
Its list of sectors and regions describes who was targeted. 
It does not say who was compromised. 
That list runs across government, defense, transportation and financial organizations in NATO member states, Ukraine, the Commonwealth of Independent States and Africa. 
Proofpoint puts US organizations on it too: government, scientific and defense industrial base entities, including nuclear installations. 
The payload mints an app-specific password named ZimbraWeb through CreateAppSpecificPasswordRequest, which can grant IMAP, POP3 or SMTP access without two-factor authentication. 
Proofpoint said TA488 went on to send further exploit emails from compromised mailservers, and could not say whether the app passwords or other stolen credentials were what got it back in. 
In the January case Seqrite analyzed, at a Ukrainian state hydrology agency, the payload also flipped zimbraPrefImapEnabled to TRUE. 
"App-specific passwords survive password resets," the researchers wrote. 
Patch, then check the accounts 
Zimbra 10.0 reached end of life on December 31, 2025, which makes 10.0.18 an emergency floor rather than a destination. 
The newest 10.1 release is 10.1.20, out July 20, which fixes four more stored XSS flaws in the Classic Web Client. 
Upgrade 10.1 deployments to at least 10.1.13, and move 10.0 deployments onto a supported 10.1 build. 
Then work the accounts. 
Any mailbox that opened or previewed a matching message in a vulnerable Classic UI session should be treated as potentially compromised: reset the password, invalidate active sessions, and regenerate 2FA scratch codes. 
Messages that landed but were never opened should be pulled and their HTML checked for the fragmented @import pattern, which Proofpoint's published YARA rule matches. 
The update does none of the checks below. 
They come from Proofpoint's and Seqrite's guidance: 
Review /opt/zimbra/log/audit.log for calls to CreateAppSpecificPassword and remove any credential named ZimbraWeb 
Find accounts with zimbraPrefImapEnabled set to TRUE that have no business need for IMAP 
Alert on SOAP calls to GetScratchCodesRequest, which should be close to absent in normal use 
Filter DNS for the published C2 domains and alert on the long random subdomain lookups the payload uses to exfiltrate 
Still running? 
How live the campaign is depends on whose telemetry you read. 
Unit 42 said threat actors continue to actively target unpatched ZCS instances using the flaw, without saying whether this cluster is among them. 
The advisory warns of ongoing activity and assesses that the group will very likely keep going after Zimbra and other Western email systems, even if this campaign winds down as organizations patch. 
Proofpoint said it "has not observed any activity from TA488 since February 2026," and tied the silence to Seqrite's disclosure and the actor tearing down its own infrastructure. 
Neither vendor's telemetry settles it. 
The Hacker News compared the two indicator lists and found the same nine domains in both, which puts Unit 42's CL-STA-1114 and Proofpoint's TA488 on the same infrastructure. 
Proofpoint's first-seen dates run from July 2025 through February 2026. 
The advisory lists LAUNDRY BEAR, Void Blizzard, CL-STA-1114, and TA488 as names in community use for these actors, while cautioning that the mapping may not be one-to-one. 
Proofpoint said it could not tie TA488 to Void Blizzard from its own telemetry, and that US government partners confirmed the association. 
Seqrite attributed its January case to APT28 with medium confidence, while Dutch intelligence, which named LAUNDRY BEAR, treats it and APT28 as separate actors. 
For defenders, the naming argument changes little. 
Patching stops the next crafted email from running. 
It does not revoke what the last one left behind, which is why the account review matters as much as the version number. 
Article reasoning-pattern comparisonThis article: 3.0%Swati Khandelwal: 2.4%The Hacker News: 1.9%Confirmation Bias3.0%This article: 5.4%Swati Khandelwal: 1.5%The Hacker News: 1.2%Anchoring Bias5.4%This article: 2.6%Swati Khandelwal: 3.5%The Hacker News: 3.3%Availability Heuristic2.6%This article: 3.7%Swati Khandelwal: 1.4%The Hacker News: 1.5%Representativeness Heuristic3.7%This article: 0.0%Swati Khandelwal: 0.7%The Hacker News: 0.6%Hindsight Bias0.0%This article: 19.6%Swati Khandelwal: 2.4%The Hacker News: 2.5%Overconfidence Bias19.6%This article: 0.5%Swati Khandelwal: 2.8%The Hacker News: 2.7%Framing Effect0.5%This article: 1.9%Swati Khandelwal: 0.9%The Hacker News: 1.0%Loss Aversion1.9%This article: 1.4%Swati Khandelwal: 0.7%The Hacker News: 0.6%Status Quo Bias1.4%This article: 0.7%Swati Khandelwal: 0.1%The Hacker News: 0.1%Sunk Cost Effect0.7%This article: 2.6%Swati Khandelwal: 1.2%The Hacker News: 1.3%Optimism Bias2.6%This article: 2.9%Swati Khandelwal: 1.9%The Hacker News: 1.6%Pessimism Bias2.9%This article: 7.3%Swati Khandelwal: 6.3%The Hacker News: 6.7%Negativity Bias7.3%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 0.8%Self-Serving Bias0.0%This article: 2.2%Swati Khandelwal: 0.4%The Hacker News: 0.4%Fundamental Attribution Error2.2%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Actor-Observer Bias0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%In-Group Bias0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.3%Out-Group Homogeneity Bias0.0%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 0.6%Halo Effect0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 3.9%Swati Khandelwal: 1.5%The Hacker News: 1.5%Recency Bias3.9%This article: 0.0%Swati Khandelwal: 0.2%The Hacker News: 0.3%Primacy Effect0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Blind-Spot Bias0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.1%Ad Hominem0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.1%Straw Man0.0%This article: 6.1%Swati Khandelwal: 3.9%The Hacker News: 4.0%Appeal to Authority6.1%This article: 3.7%Swati Khandelwal: 1.3%The Hacker News: 1.6%False Dilemma3.7%This article: 0.0%Swati Khandelwal: 0.7%The Hacker News: 0.5%Slippery Slope0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Circular Reasoning0.0%This article: 4.3%Swati Khandelwal: 3.8%The Hacker News: 4.3%Hasty Generalization4.3%This article: 0.6%Swati Khandelwal: 0.2%The Hacker News: 0.1%Red Herring0.6%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.2%Bandwagon0.0%This article: 0.2%Swati Khandelwal: 0.8%The Hacker News: 1.1%Appeal to Emotion0.2%This article: 0.0%Swati Khandelwal: 0.3%The Hacker News: 0.5%Begging the Question0.0%This article: 0.9%Swati Khandelwal: 2.0%The Hacker News: 1.9%Post Hoc (False Cause)0.9%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Tu Quoque0.0%This article: 0.0%Swati Khandelwal: 0.7%The Hacker News: 0.6%Burden of Proof0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Appeal to Nature0.0%This article: 0.0%Swati Khandelwal: 0.3%The Hacker News: 0.3%Composition/Division0.0%This article: 1.7%Swati Khandelwal: 1.1%The Hacker News: 1.0%Anecdotal1.7%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%No True Scotsman0.0%This article: 7.1%Swati Khandelwal: 2.5%The Hacker News: 2.3%Ambiguity (Equivocation)7.1%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 1.5%Swati Khandelwal: 0.2%The Hacker News: 0.1%Special Pleading1.5%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 0.0%Swati Khandelwal: 1.0%The Hacker News: 1.4%Unattributed Quote0.0%This article: 0.0%Swati Khandelwal: 0.8%The Hacker News: 0.9%Quote-first Misdirection0.0%This article: 1.1%Swati Khandelwal: 2.7%The Hacker News: 2.3%Biased Writer Voice1.1%This article: 5.2%Swati Khandelwal: 5.0%The Hacker News: 4.4%Indoctrination5.2%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 3.0%Attempt to Sell a Product or S…0.0%

1090 words analyzed.

Speakers

4speakers24%attributed speech832writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 12 words • 100.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 28 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 24 words • 0.0% coverageWriter's voice • 22 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 26 words • 0.0% coverageWriter's voice • 31 words • 0.0% coverageWriter's voice • 5 words • 0.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageProofpoint • 28 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageProofpoint • 19 words • 0.0% coverageUnit 42 • 19 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 27 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 18 words • 0.0% coverageProofpoint • 7 words • 0.0% coverageWriter's voice • 32 words • 0.0% coverageWriter's voice • 32 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 22 words • 0.0% coverageProofpoint • 17 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageProofpoint • 31 words • 0.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 5 words • 100.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 16 words • 100.0% coverageWriter's voice • 4 words • 100.0% coverageWriter's voice • 32 words • 100.0% coverageWriter's voice • 25 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageProofpoint • 12 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 2 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageUnit 42 • 23 words • 0.0% coverageWriter's voice • 32 words • 0.0% coverageProofpoint • 28 words • 0.0% coverageWriter's voice • 5 words • 0.0% coverageHacker News • 28 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 27 words • 0.0% coverageProofpoint • 22 words • 0.0% coverageSeqrite • 24 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 23 words • 0.0% coverage
Selected voice

Hacker News

100%flagged-word coverage
28 attributed words11% of attributed speech69% writer coverage
0%5.0%10.0%Indoctrination-6.9 ptsWriter: 6.9%Hacker News: 0.0%0.0%Biased Writer Voice-1.4 ptsWriter: 1.4%Hacker News: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.