Executive Summary
Since July 2025, a cluster of Russian state-supported espionage actors—tracked as LAUNDRY BEAR, TA488, TA458, and suspected APT28—has executed a sophisticated campaign targeting users of the Zimbra Collaboration Suite (ZCS) and other webmail platforms. The campaign is characterized by the use of 'half-click' or 'zero-click' exploits, primarily leveraging CVE-2025-66376, a stored XSS vulnerability in Zimbra's Classic UI. This vulnerability allowed attackers to execute arbitrary JavaScript (notably the 'ZimReaper' or 'Ulej' payloads) simply by a user viewing a crafted HTML email, requiring no further interaction such as link-clicking or attachment-opening.
The technical objective of these actors is the covert acquisition of sensitive communications. Upon successful exploitation, the payloads automatically exfiltrate the last 90 days of the victim's email, the organization's Global Address List (GAL), browser-saved passwords, and 2FA recovery codes. The activity has expanded to other webmail services including SOGo (CVE-2026-8496) and Roundcube, with actors increasingly implementing persistence mechanisms such as PHP webshells and reverse shells to maintain long-term access to compromised mail servers.
This threat poses a significant risk to government, defense industrial base, and financial sectors in NATO member states, Ukraine, and other Western allies. Because the exploits grant authenticated access to mailboxes, organizations must treat any potential view-based exposure as a full account compromise. Immediate patching of ZCS to versions 10.1.13 or 10.0.18 is critical, followed by a mandatory review of account artifacts to revoke any persistence mechanisms left behind by the actors.
Key Details
Threat Name
CVE-2025-66376
Affects
Zimbra Collaboration 10.0 before 10.0.18, Zimbra Collaboration 10.1 before 10.1.13, Zimbra Collaboration Suite (ZCS) versions prior to 10.1.13 and 10.0.18, Zimbra Collaboration Suite (ZCS), SOGo webmail platform, Zimbra Collaboration (ZCS) Suite, Zimbra webmail servers, mDaemon, Roundcube
Adversary
TA488 Other Adversaries and Aliases: APT28; LAUNDRY BEAR; TA458; TA422
MITRE Techniques
Malware/Tools
ZimReaper, Ulej, Flowerbed, Evilginx2, SpyPress
