The images in this article were generated with artificial intelligence. How we publish
A Russian state-supported espionage group has for months exploited an unknown vulnerability in Zimbra's classic web client to read Western mailboxes without the need for interaction beyond the victim's vision of the message: it is enough for the mail to be rendezvous in an authenticated session for the explosion to be fired. This "view-based" or zero-click scenario increases the operational risk because the control is in the hands of the HTML content of the mail, not in an explicit user action.
Technically, the failure identified as CVE-2025-66376 is a stored cross-site scribing in Zimbra's Classic IU that abuses the management of@ importin CSS to rebuild a< svg onload =... >fragmented - a technique called by some "tag-splitting" - and thus run JavaScript with the permissions of the affected web session. The payload described by researchers steals the CSRF token, passwords that the self-complete browser, 2FA recovery codes and uses Zimbra's internal APIs to extract data from the platform and the mailbox.

The explosion affected Zimbra Collaboration Server in previous versions of 10.0.18 and 10.1.13; the manufacturer published patches on 6 November 2025 and, later, vulnerability was included in the catalogue of exploited vulnerabilities known to CISA. For public technical references on vulnerability, see the CVE tab in the NVD and in MITRE: CVE-2025-66376 NVD sheet and CVE-2025-66376 MITRE sheet.
The malicious code, identified by some suppliers as "ZimReaper," exfiltrates data through DNS consultations with long and random subdomains, generates a TGZ file with up to 90 days of mail and, in a worrying way, creates an application password called ZimbraWeb by CreateAppSpecification Password Request. These passwords allow IMAP / POP / SMTP access without requiring 2FA, and survive conventional password changes if not explicitly revoked.
The campaign was observed by attacking government, defence, transport and finance organizations in multiple regions; public analysis is associated with clusters of actors named in a different way (LAUNDRY BEAR, Void Blizzard, TA488, CL-STA-1114), but the exact attribution is not the central point for defenders: The critical thing is that persistent exploitation can leave credentials and back doors that a simple patch does not eliminate.
From the response and mitigation perspective, there are two mandatory fronts: apply the patch and assume that accounts that visualized malicious messages may be compromised. Immediately update the affected instances to at least 10.1.13 if using branch 10.1 and bring deployments 10.0 to a supported branch; however, the patch stops new malicious shipments but does not revoke credentials already exfiltered.
Operatively, treat as potentially compromised all mailboxes that during the campaign period open or preview messages in the Classic IU. Among the essential actions: to restore passwords, to invalidate active sessions, to regenerate and force the delivery of new 2FA / scratch codes, and to revoke any app-specific password called ZimbraWeb. Search in / opt / zimbra / log / audit.log entries from CreateAppSpecificPassword and in settings accounts withzimbraPrefImapEnabledin TRUE that have no operational justification.
Detection and monitoring should include DNS alerts for queries to the domains and subdomains observed in the campaign (searches for random subdomains and long patterns), audit of unusual SOAP calls such as GetScratchCodesRequest, and HTML analysis of messages that were received but not opened: the fragmented pattern of@ importwhich rebuilds the< svg onload >is detectable by YARA rules published by suppliers.

Do not forget that the exploit takes advantage of the browser's confidence in the self-completed and in stored credentials: consider temporary policies that disable the self-completed in web access to corporate webmails, restrict the use of the Classic IU, and apply navigation controls such as proxys that can sanitize or block active HTML in post. In critical environments, immediate mitigation may include temporarily disable HTML preview to confirm cleaning and patches.
The strategic lesson is clear: mail rendering vulnerabilities are critical because they turn the mail client into a facade that gives the user's permissions to an attacker without additional clicks. For security equipment this requires combining agile parking with inventory of credentials, DNS and log monitoring, and recovery procedures that include revocation of persistent credentials and verification of access settings (IMAP / SMTP / POP) after patching.
If your organization uses Zimbra, prioritize the update, run the account checks described, and coordinate the investigation with your CSIRT or response providers. Internal communication policy should warn potentially affected users to work together in the rotation of credentials and in the identification of missing forwarding rules or messages. Effective defense of this type of campaign combines patch, account cleaning and mail channel control rather than relying on a single technical remedy.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...