Russian Espionage Groups Exploit Webmail Zero-Days
Score: 9/10

Russian Espionage Groups Exploit Webmail Zero-Days

Russian state-supported actors including LAUNDRY BEAR and TA458 are exploiting zero-day vulnerabilities in Zimbra, SOGo, and other webmail clients to exfiltrate sensitive email data from Western government and commercial targets.

Executive Summary

Since July 2025, a cluster of Russian state-supported espionage actors—tracked as LAUNDRY BEAR, TA488, TA458, and suspected APT28—has executed a sophisticated campaign targeting users of the Zimbra Collaboration Suite (ZCS) and other webmail platforms. The campaign is characterized by the use of 'half-click' or 'zero-click' exploits, primarily leveraging CVE-2025-66376, a stored XSS vulnerability in Zimbra's Classic UI. This vulnerability allowed attackers to execute arbitrary JavaScript (notably the 'ZimReaper' or 'Ulej' payloads) simply by a user viewing a crafted HTML email, requiring no further interaction such as link-clicking or attachment-opening.

The technical objective of these actors is the covert acquisition of sensitive communications. Upon successful exploitation, the payloads automatically exfiltrate the last 90 days of the victim's email, the organization's Global Address List (GAL), browser-saved passwords, and 2FA recovery codes. The activity has expanded to other webmail services including SOGo (CVE-2026-8496) and Roundcube, with actors increasingly implementing persistence mechanisms such as PHP webshells and reverse shells to maintain long-term access to compromised mail servers.

This threat poses a significant risk to government, defense industrial base, and financial sectors in NATO member states, Ukraine, and other Western allies. Because the exploits grant authenticated access to mailboxes, organizations must treat any potential view-based exposure as a full account compromise. Immediate patching of ZCS to versions 10.1.13 or 10.0.18 is critical, followed by a mandatory review of account artifacts to revoke any persistence mechanisms left behind by the actors.

Key Details

Threat Name

CVE-2025-66376

Affects

Zimbra Collaboration 10.0 before 10.0.18, Zimbra Collaboration 10.1 before 10.1.13, Zimbra Collaboration Suite (ZCS) versions prior to 10.1.13 and 10.0.18, Zimbra Collaboration Suite (ZCS), SOGo webmail platform, Zimbra Collaboration (ZCS) Suite, Zimbra webmail servers, mDaemon, Roundcube

Adversary

TA488 Other Adversaries and Aliases: APT28; LAUNDRY BEAR; TA458; TA422

Malware/Tools

ZimReaper, Ulej, Flowerbed, Evilginx2, SpyPress

Report Score

9out of 10
Quality Score
Excellent
IOC Quality9
TTP Details9
Detection Guidance7
Enterprise Relevance10
Clarity & Structure10
Technical Depth9

Sources