“Half-Click” Zimbra Email Attack Steals 90 Days

Proofpoint · High sophistication
Last updated August 17, 2026

CISA warns a Russian state-sponsored group (“Laundry Bear,” tracked by Microsoft as “Void Blizzard”) is compromising some unpatched Zimbra email accounts when users merely open or preview a specially crafted email. The hidden code can steal passwords, MFA-related tokens, and up to 90 days of messages, and may also create an app passcode that keeps the attacker’s access even after a password change. The same campaign also uses realistic fake login pages and lookalike Zimbra domains to capture credentials and session cookies.

How the attack worked

According to CISA, this campaign can compromise certain unpatched Zimbra email accounts simply when a user opens or previews a malicious message in webmail. Attackers embed malicious JavaScript inside a specially crafted HTML email, which runs automatically when the webmail client renders the message. Because no link click is technically required, Proofpoint describes it as a "half-click" attack: the victim only needs to open the email or let it appear in a preview pane.

Once triggered, the code can collect passwords, authentication data, and as much as 90 days of stored messages. It can also copy the Global Address List, giving attackers material for further impersonation attempts against colleagues and partners. In some cases, the attack creates a new Zimbra application passcode and sends it back to the attacker, which can preserve access even after the victim changes their password.

Why it succeeded

The attack targets unpatched Zimbra systems, meaning the technical exploit does the initial work rather than tricking a user into an obvious mistake. This is compounded by a second track: adversary-in-the-middle phishing kits that present login pages closely resembling legitimate email portals, hosted on lookalike domains such as mailnalysis.com and zimbrastat.com. Lures observed by Proofpoint included messages sent from attacker-controlled Proton Mail accounts, with pretexts like a partnership proposal from a media-verification organization around EU disinformation cooperation, an approach designed to look like routine, legitimate outreach rather than an obvious phishing attempt.

What to watch for

  • Unexpected partnership or cooperation emails from unfamiliar senders, especially those using external mail infrastructure
  • Login prompts or webmail pages reached via an email link rather than a known, bookmarked address
  • Domain names that closely resemble Zimbra but are slightly altered
  • Unexpected application passcodes, particularly ones labeled "ZimbraWeb"
  • Emails that seem harmless in content but rely on rendering HTML in a preview pane

How to build resistance

Organizations should reinforce that clicking isn't the only risk, simply previewing an email on an unpatched system can be enough for compromise, so suspicious messages should be reported rather than just left unclicked. Staff should be trained to navigate directly to their organization's known webmail address instead of following email links, and to treat unexpected re-authentication prompts with suspicion. IT and admin teams should routinely check for unusual application passcodes and mailbox forwarding rules as persistence indicators. Finally, keeping webmail platforms patched remains essential: strong passwords and trained employees cannot fully protect against an exposed, unpatched email server.

Key findings

  • CISA says Laundry Bear can compromise certain Zimbra email accounts when a user “simply opens or previews a malicious message” on unpatched systems.
  • Attackers embed “malicious JavaScript inside a specially crafted HTML email” which runs when the webmail client displays the message (a “zero-click” / “half-click” style exploit).
  • The malicious code can collect “passwords, authentication data and as much as 90 days of messages,” plus copy the Global Address List for follow-on impersonation.
  • The attack may create a new “Zimbra application passcode” to preserve access even after password changes; CISA urged admins to look for suspicious passcodes labeled “ZimbraWeb.”
  • Laundry Bear also uses adversary-in-the-middle phishing kits with fake email login pages and Zimbra lookalike domains (e.g., mailnalysis.com, zimbrastat.com).
  • Proofpoint observed lures sent from “attacker-controlled Proton Mail accounts,” including a pretext about cooperating on EU disinformation efforts with a legitimate-looking EU events calendar link.

Who’s being targeted

  • Commonly targeted roles: All employees (webmail users), Executives, Communications/PR, Government program staff, IT administrators, Security operations (SOC).
  • Affected industries: Defense industrial base, Government, Education, Energy, Law enforcement, Media, Nonprofit, Technology.
  • Attack channels: email, website.
  • Impersonated: A Belgian media-verification organization, Zimbra (lookalike Zimbra infrastructure / email portal).

Red flags to watch for

  • Unexpected external partnership pitch with pressure to review quickly
  • Email appears harmless but relies on viewing HTML content in webmail
  • Sender is not a known contact and uses external mail infrastructure
  • Login domain is a lookalike (not the organization’s known webmail URL)
  • Unexpected prompt to re-authenticate
  • Domain names that resemble Zimbra but are slightly off
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is a half-click email attack?

It's an attack where malicious JavaScript embedded in a specially crafted HTML email runs simply when a user opens or previews the message in webmail, without requiring any link click.

What data can this Zimbra attack steal?

The malicious code can collect passwords, authentication data, and as much as 90 days of messages, plus copy the Global Address List for follow-on impersonation.

How does the attacker maintain access after a password change?

The attack may create a new Zimbra application passcode, which can preserve attacker access even after the victim changes their password. CISA urged admins to watch for suspicious passcodes labeled ZimbraWeb.

Are there other tactics used besides the email exploit?

Yes, the same campaign also uses adversary-in-the-middle phishing kits with fake login pages and Zimbra lookalike domains to capture credentials and session cookies.

Read the video transcript

With this Zimbra attack, you don’t even have to click. Just previewing the email can hand over 90 days of your inbox. CISA says the group Laundry Bear hides malicious JavaScript in a crafted HTML email. When Zimbra previews it, the code quietly grabs your password, MFA data, and up to 90 days of messages, and can drop a sneaky 'ZimbraWeb' app passcode so they stay in, even after you change yours. Same campaign, second trick: adversary-in-the-middle phishing pages. You get an email from a Proton Mail address about EU disinformation work, click the link, and land on a fake Zimbra login at mailnalysis.com or zimbrastat.com that looks almost perfect, while it steals your credentials and session cookie. Here’s the move: if anything pushes you to log in or even just preview in Zimbra and it feels off, Proton Mail sender, odd domain, surprise login prompt, stop and report it to Security, then go to your normal Zimbra URL yourself.

Similar attacks

Quishing Emails Use QR Codes to Bypass Filters

Quishing Emails Use QR Codes to Bypass Filters

The article describes how attackers use QR codes in emails (“quishing”) to hide malicious links, push victims onto less-protected mobile phones, and steal credentials or MFA tokens. It also cites an FBI notice describing North Korea’s Kimsuky using QR codes in spearphishing emails targeting think…

August 18, 2026
BlueMoon Phishing Lures Drop Chrome Zero-Day Chain

BlueMoon Phishing Lures Drop Chrome Zero-Day Chain

Researchers found multiple espionage groups using the same Chrome+Windows exploit kit (“BlueMoon”) within days of each other. The groups sent realistic phishing emails (internship requests, conference outreach, procurement inquiries, and vaccination appointments) that pushed victims to click links…

September 10, 2026
Kali365 OAuth Phish Bypasses Password Theft

Kali365 OAuth Phish Bypasses Password Theft

The article describes an FBI-warned phishing operation (Kali365) that tricks Microsoft 365 users into approving access via a real Microsoft device-code login flow, often without stealing a password. Victims are lured with document-sharing themed emails and prompted to enter a device code,…

September 8, 2026
DocuSign Share Lure Steals Microsoft 365 Sessions

DocuSign Share Lure Steals Microsoft 365 Sessions

Researchers described an active phishing operation using real DocuSign notifications to trick employees into opening a fake “remittance-advice” document and clicking a hidden malicious link. The attack routes victims through legitimate Microsoft/Google pages before landing on an…

August 28, 2026
NovaCookies Uses Real DocuSign to Steal M365 Sessions

NovaCookies Uses Real DocuSign to Steal M365 Sessions

Researchers report NovaCookies, a phishing-as-a-service toolkit that steals Microsoft 365 session cookies by proxying real logins in real time. The campaigns abuse genuine DocuSign email notifications to deliver a malicious document link that ultimately leads to an attacker-controlled Microsoft 365…

August 26, 2026
APT Groups Lure Targets Into Fake Zoom/Teams Meets

APT Groups Lure Targets Into Fake Zoom/Teams Meets

This threat trend report describes multiple real-world APT campaigns where attackers rely on social engineering and trusted services (Zoom/Teams, Telegram, webmail, GitHub) to steal credentials and access cloud accounts. Notable examples include fake meeting lures to deliver malware, and abuse of…

August 20, 2026