“Half-Click” Zimbra Email Attack Steals 90 Days

Proofpoint · High sophistication
Last updated August 17, 2026

CISA warns a Russian state-sponsored group (“Laundry Bear,” tracked by Microsoft as “Void Blizzard”) is compromising some unpatched Zimbra email accounts when users merely open or preview a specially crafted email. The hidden code can steal passwords, MFA-related tokens, and up to 90 days of messages, and may also create an app passcode that keeps the attacker’s access even after a password change. The same campaign also uses realistic fake login pages and lookalike Zimbra domains to capture credentials and session cookies.

How the attack worked

According to CISA, this campaign can compromise certain unpatched Zimbra email accounts simply when a user opens or previews a malicious message in webmail. Attackers embed malicious JavaScript inside a specially crafted HTML email, which runs automatically when the webmail client renders the message. Because no link click is technically required, Proofpoint describes it as a "half-click" attack: the victim only needs to open the email or let it appear in a preview pane.

Once triggered, the code can collect passwords, authentication data, and as much as 90 days of stored messages. It can also copy the Global Address List, giving attackers material for further impersonation attempts against colleagues and partners. In some cases, the attack creates a new Zimbra application passcode and sends it back to the attacker, which can preserve access even after the victim changes their password.

Why it succeeded

The attack targets unpatched Zimbra systems, meaning the technical exploit does the initial work rather than tricking a user into an obvious mistake. This is compounded by a second track: adversary-in-the-middle phishing kits that present login pages closely resembling legitimate email portals, hosted on lookalike domains such as mailnalysis.com and zimbrastat.com. Lures observed by Proofpoint included messages sent from attacker-controlled Proton Mail accounts, with pretexts like a partnership proposal from a media-verification organization around EU disinformation cooperation, an approach designed to look like routine, legitimate outreach rather than an obvious phishing attempt.

What to watch for

  • Unexpected partnership or cooperation emails from unfamiliar senders, especially those using external mail infrastructure
  • Login prompts or webmail pages reached via an email link rather than a known, bookmarked address
  • Domain names that closely resemble Zimbra but are slightly altered
  • Unexpected application passcodes, particularly ones labeled "ZimbraWeb"
  • Emails that seem harmless in content but rely on rendering HTML in a preview pane

How to build resistance

Organizations should reinforce that clicking isn't the only risk, simply previewing an email on an unpatched system can be enough for compromise, so suspicious messages should be reported rather than just left unclicked. Staff should be trained to navigate directly to their organization's known webmail address instead of following email links, and to treat unexpected re-authentication prompts with suspicion. IT and admin teams should routinely check for unusual application passcodes and mailbox forwarding rules as persistence indicators. Finally, keeping webmail platforms patched remains essential: strong passwords and trained employees cannot fully protect against an exposed, unpatched email server.

Key findings

  • CISA says Laundry Bear can compromise certain Zimbra email accounts when a user “simply opens or previews a malicious message” on unpatched systems.
  • Attackers embed “malicious JavaScript inside a specially crafted HTML email” which runs when the webmail client displays the message (a “zero-click” / “half-click” style exploit).
  • The malicious code can collect “passwords, authentication data and as much as 90 days of messages,” plus copy the Global Address List for follow-on impersonation.
  • The attack may create a new “Zimbra application passcode” to preserve access even after password changes; CISA urged admins to look for suspicious passcodes labeled “ZimbraWeb.”
  • Laundry Bear also uses adversary-in-the-middle phishing kits with fake email login pages and Zimbra lookalike domains (e.g., mailnalysis.com, zimbrastat.com).
  • Proofpoint observed lures sent from “attacker-controlled Proton Mail accounts,” including a pretext about cooperating on EU disinformation efforts with a legitimate-looking EU events calendar link.

Who’s being targeted

  • Commonly targeted roles: All employees (webmail users), Executives, Communications/PR, Government program staff, IT administrators, Security operations (SOC).
  • Affected industries: Defense industrial base, Government, Education, Energy, Law enforcement, Media, Nonprofit, Technology.
  • Attack channels: email, website.
  • Impersonated: A Belgian media-verification organization, Zimbra (lookalike Zimbra infrastructure / email portal).

Red flags to watch for

  • Unexpected external partnership pitch with pressure to review quickly
  • Email appears harmless but relies on viewing HTML content in webmail
  • Sender is not a known contact and uses external mail infrastructure
  • Login domain is a lookalike (not the organization’s known webmail URL)
  • Unexpected prompt to re-authenticate
  • Domain names that resemble Zimbra but are slightly off
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is a half-click email attack?

It's an attack where malicious JavaScript embedded in a specially crafted HTML email runs simply when a user opens or previews the message in webmail, without requiring any link click.

What data can this Zimbra attack steal?

The malicious code can collect passwords, authentication data, and as much as 90 days of messages, plus copy the Global Address List for follow-on impersonation.

How does the attacker maintain access after a password change?

The attack may create a new Zimbra application passcode, which can preserve attacker access even after the victim changes their password. CISA urged admins to watch for suspicious passcodes labeled ZimbraWeb.

Are there other tactics used besides the email exploit?

Yes, the same campaign also uses adversary-in-the-middle phishing kits with fake login pages and Zimbra lookalike domains to capture credentials and session cookies.

Read the video transcript

With this Zimbra attack, you don’t even have to click. Just previewing the email can hand over 90 days of your inbox. CISA says the group Laundry Bear hides malicious JavaScript in a crafted HTML email. When Zimbra previews it, the code quietly grabs your password, MFA data, and up to 90 days of messages, and can drop a sneaky 'ZimbraWeb' app passcode so they stay in, even after you change yours. Same campaign, second trick: adversary-in-the-middle phishing pages. You get an email from a Proton Mail address about EU disinformation work, click the link, and land on a fake Zimbra login at mailnalysis.com or zimbrastat.com that looks almost perfect, while it steals your credentials and session cookie. Here’s the move: if anything pushes you to log in or even just preview in Zimbra and it feels off, Proton Mail sender, odd domain, surprise login prompt, stop and report it to Security, then go to your normal Zimbra URL yourself.

Similar attacks

Zimbra Zero-Day Email: Preview Triggers Espionage

Zimbra Zero-Day Email: Preview Triggers Espionage

A Russia-aligned espionage group sent specially crafted HTML emails that could compromise vulnerable Zimbra webmail servers just by being opened or previewed, no link clicks or attachments needed. The exploit ran JavaScript inside the email body to steal mailbox data and credentials, then set up…

July 24, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Hotel Wi‑Fi Lures Steal M365 Logins, Drop Malware

Hotel Wi‑Fi Lures Steal M365 Logins, Drop Malware

Microsoft says Russian-linked threat actors compromised hotel and conference guest Wi‑Fi “captive portal” networks to redirect travelers to fake Microsoft 365 sign-in pages, device-code phishing, or fake update pages. The goal was to steal cloud credentials (including Entra ID device codes) and…

August 4, 2026
Fake Defense Summit Invites Hit Dutch Police

Fake Defense Summit Invites Hit Dutch Police

A Russian-linked group allegedly stole sensitive contact data from the Netherlands National Police after getting access to an employee’s email account. The podcast describes a realistic spearphishing lure: an email invitation to a “European Defence Summit” that includes a link or a QR code in a PDF…

July 23, 2026
Deepfake FBI Videos Push Victims to Fake IC3 Sites

Deepfake FBI Videos Push Victims to Fake IC3 Sites

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into sharing more personal and financial information. In one example, victims are contacted on Facebook Messenger by someone posing as an FBI…

July 21, 2026
Lazarus Lures Staff With Fake Jobs to Drop Malware

Lazarus Lures Staff With Fake Jobs to Drop Malware

Researchers tied North Korea’s Lazarus Group to a real-world campaign that approaches professionals with convincing fake recruiter outreach and job offers. Victims are tricked into opening a malicious PDF or installing a fake PDF viewer from lookalike websites, which then installs backdoors and can…

August 12, 2026