This Russian Cybercrime Campaign Can Infect a User Simply by Viewing an Email


  • Proofpoint reports that Russian TA488 exploited Zimbra Zero Day CVE‑2025‑66376 in espionage campaigns
  • A “half-click exploit” allows attackers to compromise systems when victims simply view malicious emails.
  • Targets included NATO, the Ukrainian government and defense entities; the group disappeared after an exhibition in February 2026

Russian state-sponsored cybercriminals have abused a zero-day vulnerability in messaging and collaboration platform Zimbra to carry out espionage against Western targets – primarily military and government agencies, experts have warned.

Cybersecurity researchers Proofpoint say the campaign has been going on for at least a year, if not more, describing it as a “half-click exploit” because victims don’t even need to do anything specific to become infected.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top