This Russian cybercrime campaign can infect a user just by viewing an email
- Proofpoint reports Russian TA488 exploited Zimbra zero‑day CVE‑2025‑66376 in espionage campaigns
- “Half‑click exploit” let attackers compromise systems when victims merely viewed malicious emails
- Targets included NATO, Ukrainian government, and defense entities; group vanished after Feb 2026 exposure
Russian state-sponsored cybercriminals have been abusing a zero-day vulnerability in the Zimbra email and collaboration platform to conduct espionage against western targets – primarily military and government agencies, experts have warned.
Cybersecurity researchers Proofpoint claim the campaign has been ongoing for at least a year, possibly longer, describing it as a “half-click exploit”, because the victims don’t even need to do anything specific in order to get infected.
Usually, when an attack is done via email, the victim is required to at least download a file or click a link. In this case, a cross-site scripting (XSS) vulnerability in the Zimbra web-based email service allowed the Russians to infiltrate the computers as soon as the victim views the email, nothing more.
Latest Videos FromTechRadar
Targeting NATO and Ukraine
The vulnerability in question is now tracked as CVE-2025-66376. It was assigned a severity score of 7.2/10 (high), and was patched in November 2025. However, the threat actors have been leveraging it long before Zimbra patched it up.
Proofpoint says numerous groups were observed, throughout the years, abusing this flaw. This time around, though, the group in question is tracked as TA488, also known as Laundry Bear or Void Blizzard.
“After successful exploitation, TA488 established persistent access to the systems and exfiltrated emails from the targeted users,” Proofpoint’s report reads. Besides emails, the crooks hunted for passwords, email directories, two-factor authentication tokens, and more. The group has been “consistently” targeting NATO and Ukrainian government organizations, alongside entities in the defense industrial base,
The group seems to be defunct now, since the researchers could not find any activity post February 2026. At that time, security researchers Seqrite disclosed a detailed breakdown of the group’s infrastructure and modus operandi, resulting in TA488 burning down months-old setups and vanishing.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

The best antivirus for all budgets

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Source
Proofpoint reports Russian TA488 exploited Zimbra zero‑day CVE‑2025‑66376 in espionage campaigns “Half‑click exploit” let attackers compromise systems when victims merely viewed malicious emails Targets included NATO, Ukrainian government, and defense entities; group vanished after Feb 2026 exposure Russian state-sponsored cybercriminals have been abusing a zero-day vulnerability in the Zimbra email…
Recent Posts
- I swapped my iPhone’s camera for this Y2K-inspired digicam — and there’s only one point-and-shoot I want in my pocket for capturing memories
- X Money is launching in the US starting today
- X Money begins limited US rollout
- Quote of the day by Barack Obama: ‘Our new information ecosystem is turbocharging some of humanity’s worst impulses’ — a warning against rampant disinformation
- Razer’s analog Huntsman V3 Pro is over 20 percent off
Archives
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023