Zimbra under attack zero-click: CVE-2025-66376 steals credentials and access mailboxes without user interaction

Author: Published 4 min de lectura 187 reading

The images in this article were generated with artificial intelligence. How we publish

A Russian state-supported espionage group has for months exploited an unknown vulnerability in Zimbra's classic web client to read Western mailboxes without the need for interaction beyond the victim's vision of the message: it is enough for the mail to be rendezvous in an authenticated session for the explosion to be fired. This "view-based" or zero-click scenario increases the operational risk because the control is in the hands of the HTML content of the mail, not in an explicit user action.

Technically, the failure identified as CVE-2025-66376 is a stored cross-site scribing in Zimbra's Classic IU that abuses the management of@ importin CSS to rebuild a< svg onload =... >fragmented - a technique called by some "tag-splitting" - and thus run JavaScript with the permissions of the affected web session. The payload described by researchers steals the CSRF token, passwords that the self-complete browser, 2FA recovery codes and uses Zimbra's internal APIs to extract data from the platform and the mailbox.

Zimbra under attack zero-click: CVE-2025-66376 steals credentials and access mailboxes without user interaction
Image generated with IA.

The explosion affected Zimbra Collaboration Server in previous versions of 10.0.18 and 10.1.13; the manufacturer published patches on 6 November 2025 and, later, vulnerability was included in the catalogue of exploited vulnerabilities known to CISA. For public technical references on vulnerability, see the CVE tab in the NVD and in MITRE: CVE-2025-66376 NVD sheet and CVE-2025-66376 MITRE sheet.

The malicious code, identified by some suppliers as "ZimReaper," exfiltrates data through DNS consultations with long and random subdomains, generates a TGZ file with up to 90 days of mail and, in a worrying way, creates an application password called ZimbraWeb by CreateAppSpecification Password Request. These passwords allow IMAP / POP / SMTP access without requiring 2FA, and survive conventional password changes if not explicitly revoked.

The campaign was observed by attacking government, defence, transport and finance organizations in multiple regions; public analysis is associated with clusters of actors named in a different way (LAUNDRY BEAR, Void Blizzard, TA488, CL-STA-1114), but the exact attribution is not the central point for defenders: The critical thing is that persistent exploitation can leave credentials and back doors that a simple patch does not eliminate.

From the response and mitigation perspective, there are two mandatory fronts: apply the patch and assume that accounts that visualized malicious messages may be compromised. Immediately update the affected instances to at least 10.1.13 if using branch 10.1 and bring deployments 10.0 to a supported branch; however, the patch stops new malicious shipments but does not revoke credentials already exfiltered.

Operatively, treat as potentially compromised all mailboxes that during the campaign period open or preview messages in the Classic IU. Among the essential actions: to restore passwords, to invalidate active sessions, to regenerate and force the delivery of new 2FA / scratch codes, and to revoke any app-specific password called ZimbraWeb. Search in / opt / zimbra / log / audit.log entries from CreateAppSpecificPassword and in settings accounts withzimbraPrefImapEnabledin TRUE that have no operational justification.

Detection and monitoring should include DNS alerts for queries to the domains and subdomains observed in the campaign (searches for random subdomains and long patterns), audit of unusual SOAP calls such as GetScratchCodesRequest, and HTML analysis of messages that were received but not opened: the fragmented pattern of@ importwhich rebuilds the< svg onload >is detectable by YARA rules published by suppliers.

Zimbra under attack zero-click: CVE-2025-66376 steals credentials and access mailboxes without user interaction
Image generated with IA.

Do not forget that the exploit takes advantage of the browser's confidence in the self-completed and in stored credentials: consider temporary policies that disable the self-completed in web access to corporate webmails, restrict the use of the Classic IU, and apply navigation controls such as proxys that can sanitize or block active HTML in post. In critical environments, immediate mitigation may include temporarily disable HTML preview to confirm cleaning and patches.

The strategic lesson is clear: mail rendering vulnerabilities are critical because they turn the mail client into a facade that gives the user's permissions to an attacker without additional clicks. For security equipment this requires combining agile parking with inventory of credentials, DNS and log monitoring, and recovery procedures that include revocation of persistent credentials and verification of access settings (IMAP / SMTP / POP) after patching.

If your organization uses Zimbra, prioritize the update, run the account checks described, and coordinate the investigation with your CSIRT or response providers. Internal communication policy should warn potentially affected users to work together in the rotation of credentials and in the identification of missing forwarding rules or messages. Effective defense of this type of campaign combines patch, account cleaning and mail channel control rather than relying on a single technical remedy.

Coverage

Related

More news on the same subject.