This Russian cybercrime campaign can infect a user just by viewing an email



  • Proofpoint Reports Russian TA488 Exploited Zimbra Zero-Day CVE-2025-66376 in Espionage Campaigns
  • The “half-click exploit” allows attackers to compromise systems when victims simply view malicious emails
  • Targets included NATO, the Ukrainian government, and defense entities; The group disappeared after the exhibition in February 2026.

Russian state-sponsored cybercriminals have been abusing a zero-day vulnerability in the Zimbra email and collaboration platform to conduct espionage against Western targets, primarily military and government agencies, experts have warned.

Cybersecurity researchers Proofpoint say the campaign has been running for at least a year, possibly more, and describe it as a “half-click exploit” because victims don’t even need to do anything specific to get infected.

Leave a Comment

Your email address will not be published. Required fields are marked *