Russian espionage campaign exploits Zimbra flaw without a single click

Unit 42 at Palo Alto Networks has uncovered a persistent espionage campaign with Russian links. The campaign exploits CVE-2025-66376 in unpatched installations of Zimbra Collaboration Suite. The activity is tracked as CL-STA-1114, and it overlaps with the threat actor known as Void Blizzard or LAUNDRY BEAR. According to Unit 42, the campaign has targeted government, defence, transport and financial organisations across NATO member states, Ukraine, CIS countries and Africa.

What happens technically

Zimbra Collaboration Suite is an email and collaboration platform that organisations run in their own environments, and users access it through the browser. The vulnerability makes it possible to hide active code inside the HTML content of an email. When the recipient opens the message in webmail, the browser executes the hidden code as part of rendering it. The attack therefore requires no attachment to be opened and no link to be clicked. Displaying the message is sufficient on its own.

The injected code runs inside the recipient’s authenticated session, and it inherits every permission that session already holds. According to Unit 42, this is used to extract credentials, two-factor authentication scratch codes, system information and up to 90 days of email and search history. The extraction happens in the background while the user reads the email, and an ordinary user will rarely notice anything. Unit 42 has published technical indicators that organisations can search for in their own logs.

Attackersends the emailEmail with hidden codethe victim opens itZimbra webmailsigned in sessionsilent exfiltrationThe attacker's serverpasswords, email archive, one-time codes
Figure: The attack chain: an email with hidden code is opened in Zimbra webmail, the code runs in the victim's signed in session, and passwords, the email archive and one-time codes are quietly sent to the attacker's server.

What this means for you if you run Zimbra yourself

Berigo's assessment is that this attack bypasses most of the security training you have invested in. Nobody on your staff makes a mistake here. There is therefore no mistake to train away. The protection has to live in the technology, and above all in the vulnerability actually being patched in your environment.

If your webmail is exposed to the internet, it is a direct attack surface in this campaign. If you carry security responsibility in government, defence, transport or finance, you fall inside the target groups Unit 42 describes. Norwegian NATO membership is what places you there. We also see the theft of one-time codes as an important limitation of traditional two-factor authentication. Codes that a script can read are codes that can be stolen. They then no longer provide the protection your risk assessment may assume.

Berigo recommends

  • Patch every Zimbra installation immediately, prioritising those exposed to the internet.
  • Search logs for the indicators published by Unit 42, and treat any hit as an ongoing incident.
  • Consider phishing-resistant two-factor authentication, such as FIDO2 or passkeys, wherever one-time codes are used today. One-time codes were stolen in this campaign.
  • Review whether webmail needs to be openly exposed, or whether the service can sit behind VPN or other access controls.

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch