Russian campaign against Zimbra with zero-click exploit and theft of emails and 2FA codes
Several Russia-linked groups exploited an as-yet-unknown vulnerability in Zimbra for months to target government and strategic organizations in the West. The vector was particularly dangerous because simply opening or even just viewing the email message in the web client was enough to trigger the exploit, with no explicit click required from the user. Once inside, the attackers targeted email inboxes from the last 90 days, the entire address book, passwords saved in the browser, and the codes used for 2FA recovery. The campaigns involved targets in Ukraine, the United States, and other high-profile entities, with strong interest in government agencies, defense, and research. Proofpoint and other security organizations have highlighted that these actors have an exploit chain for webmail servers, a sign of advanced and persistent operational capability. The case shows how critical the risk tied to email still is, especially when combined with access to credentials and authentication tokens. The report also reinforces the idea that MFA alone is not enough if an attacker can intercept sessions or recovery codes.
Sources
- Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets — Dark Reading
- Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes — The Hacker News
- Russian Hackers Exploit New ‘Zero-Click’ Attack Against Western Organizations — www.infosecurity-magazine.com
- ta458 roundpress exploits — Proofpoint Threat Insight
- TA488 Targets Zimbra Mailservers with Half-Click Exploits — Proofpoint Threat Insight


Leave a Reply