- Proofpoint reports that Russian TA488 exploited Zimbra Zero Day CVE‑2025‑66376 in espionage campaigns
- A “half-click exploit” allows attackers to compromise systems when victims simply view malicious emails.
- Targets included NATO, the Ukrainian government and defense entities; the group disappeared after an exhibition in February 2026
Russian state-sponsored cybercriminals have abused a zero-day vulnerability in messaging and collaboration platform Zimbra to carry out espionage against Western targets – primarily military and government agencies, experts have warned.
Cybersecurity researchers Proofpoint say the campaign has been going on for at least a year, if not more, describing it as a “half-click exploit” because victims don’t even need to do anything specific to become infected.
Usually, when an attack is carried out via email, the victim must at least download a file or click on a link. In this case, a cross-site scripting (XSS) vulnerability in the Zimbra webmail service allowed the Russians to infiltrate computers as soon as the victim viewed the email, nothing more.
Latest videos fromTechRadar
Targeting NATO and Ukraine
The vulnerability in question is now identified as CVE-2025-66376. It was assigned a severity score of 7.2/10 (high) and was patched in November 2025. However, threat actors exploited it long before Zimbra patched it.
Proofpoint says that many groups have been observed over the years abusing this flaw. This time around, however, the group in question is being tracked as TA488, also known as Laundry Bear or Void Blizzard.
“After successful exploitation, TA488 established persistent access to systems and exfiltrated emails from targeted users,” the Proofpoint report said. Besides emails, the scammers were looking for passwords, email directories, two-factor authentication tokens, and more. The group “systematically” targeted NATO and Ukrainian government organizations, as well as defense industrial base entities,
The group appears to be defunct now, as researchers found no activity after February 2026. Around that time, security researchers Seqrite disclosed a detailed breakdown of the group’s infrastructure and modus operandi, leading TA488 to burn months-old configurations and disappear.
The best antivirus for every budget
Follow TechRadar on Google News And add us as your favorite source to get our news, reviews and expert opinions in your feeds.




