- Proofpoint Reports Russian TA488 Exploited Zimbra Zero-Day CVE-2025-66376 in Espionage Campaigns
- The “half-click exploit” allows attackers to compromise systems when victims simply view malicious emails
- Targets included NATO, the Ukrainian government, and defense entities; The group disappeared after the exhibition in February 2026.
Russian state-sponsored cybercriminals have been abusing a zero-day vulnerability in the Zimbra email and collaboration platform to conduct espionage against Western targets, primarily military and government agencies, experts have warned.
Cybersecurity researchers Proofpoint say the campaign has been running for at least a year, possibly more, and describe it as a “half-click exploit” because victims don’t even need to do anything specific to get infected.
Typically, when an attack is carried out via email, the victim must at least download a file or click on a link. In this case, a cross-site scripting (XSS) vulnerability in the web-based email service Zimbra allowed the Russians to infiltrate computers as soon as the victim sees the email, nothing more.
Latest videos ofTechnologyRadar
Targeting NATO and Ukraine
The vulnerability in question is now tracked as CVE-2025-66376. It was assigned a severity score of 7.2/10 (high) and was patched in November 2025. However, threat actors have been exploiting it long before Zimbra patched it.
Proofpoint states that over the years, numerous groups have been observed abusing this flaw. This time, however, the group in question is tracked as TA488, also known as Laundry Bear or Void Blizzard.
“After a successful exploit, TA488 established persistent access to the systems and exfiltrated emails from targeted users,” the Proofpoint report reads. In addition to emails, the criminals searched for passwords, email directories, two-factor authentication tokens, and more. The group has been “consistently” targeting NATO and Ukrainian government organizations, along with defense industrial base entities.
The group appears to be gone now, as researchers were unable to find any activity after February 2026. At the time, security researchers Seqrite revealed a detailed breakdown of the group’s infrastructure and modus operandi, causing TA488 to burn months-old configurations and disappear.
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.




