
Zimbra Zero-Day Email: Preview Triggers Espionage
A Russia-aligned espionage group sent specially crafted HTML emails that could compromise vulnerable Zimbra webmail servers just by being opened or previewed,…
Russian-linked threat actors sent generic-looking informational emails that required no clicking, but simply opening them in vulnerable Outlook Web Access (OWA) could trigger a hidden exploit. The campaign targeted government and multiple industries, then installed a stealthy browser-based implant designed to keep mailbox access even after password resets or device rebuilds.
This campaign relied on a “half-click” exploit chain: opening or viewing an email in a vulnerable version of Outlook Web Access (OWA) was enough to trigger compromise, no clicking required beyond reading the message. The emails were deliberately vague, labeled as informational updates with wording like "no action required," and mimicked harmless content such as supply chain analyses, research updates, or tourism and gas market metrics. None of the messages contained links or attachments, which removed the usual visual cues defenders and filters look for.
Once a recipient opened the email in a vulnerable OWA session, the flaw tracked as CVE-2026-42897 delivered a browser-based implant referred to as "OWAReaper." This implant was designed for persistence and mailbox takeover, and it was built to survive normal remediation steps like password resets or reimaging the affected device.
The approach succeeded because it removed the traditional "tell" that awareness training focuses on: suspicious links or attachments. By excluding both, the messages felt low-risk and were more likely to be opened and skimmed rather than deleted or reported. The generic, mass-mailing style of the lures also helped the emails blend into ordinary spam rather than stand out as a targeted threat, letting the campaign reach a broad set of organizations across government, telecommunications, financial services, hospitality, and aerospace sectors.
Security teams should reinforce that the absence of links or attachments does not make an email safe, particularly on unpatched webmail platforms. Staff using OWA, government and contractor personnel, and teams in finance, telecommunications, and aerospace should be encouraged to report vague "no action required" emails rather than dismiss them as harmless spam. Incident response processes should also account for server-side persistence, meaning suspected compromises require deliberate removal from the Exchange server rather than relying solely on credential rotation or device rebuilds.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It is an exploit where simply opening or viewing an email in vulnerable webmail is enough to trigger compromise, without the recipient clicking any link or attachment.
Attackers intentionally excluded links and attachments so the message would look harmless and legitimate, increasing the chance the recipient would open and read it, which alone fired the exploit.
No. This persistent access lives on the server side, so credential rotation and even full re-imaging of the targeted device will not evict the actor without deliberate removal from the Exchange server.
Targets included U.S. and European government entities and organizations in telecommunications, financial, hospitality, and aerospace sectors.
Imagine an email that hacks your mailbox just because you read it in Outlook Web Access, no links, no attachments. Laundry Bear, also called TA488, is abusing a bug in OWA, CVE-2026-42897. Their "half-click" emails look like boring updates, supply chain research, tourism or gas market metrics, sent from Proton Mail or even a compromised coworker. The second you view it in vulnerable OWA, the exploit fires and drops a browser implant called OWAReaper. It quietly takes over your mailbox and can survive password changes and even a full device rebuild. If you see a vague "no action required" bulletin in OWA that feels out of place, stop and report it to Security, don’t open it in the web browser.

A Russia-aligned espionage group sent specially crafted HTML emails that could compromise vulnerable Zimbra webmail servers just by being opened or previewed,…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in…

A Russian-aligned group (TA488) used malicious emails to exploit a Zimbra webmail flaw so that simply opening or previewing a message triggered compromise, no…

Government agencies and security firms warn that Russia-aligned hackers are using “zero-click” phishing emails to compromise organizations using Zimbra…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…