TA488 “Half-Click” Emails Hack Zimbra Webmail

eSecurity Planet · High sophistication
Last updated July 30, 2026

A Russian-aligned group (TA488) used malicious emails to exploit a Zimbra webmail flaw so that simply opening or previewing a message triggered compromise, no link click or attachment required. The attackers then stole email data and set up persistent access to compromised mail servers, including by creating an app password named “ZimbraWeb.” The campaign focused on Ukrainian and U.S. government-related organizations, plus defense and scientific groups.

How the attack worked

TA488 exploited a Zimbra webmail vulnerability, CVE-2025-66376, for at least five months. What set this campaign apart is that victims did not need to click a link or open an attachment. Simply opening or previewing the malicious email in a vulnerable Zimbra client was enough to execute embedded JavaScript and trigger the exploit. This is often called a half-click attack because the only action required is viewing the message.

Once triggered, the ZimReaper malware harvested tokens, passwords, and 2FA recovery codes from the mailbox. Attackers also created an application-specific password named ZimbraWeb, giving them persistent IMAP, POP3, and SMTP access that bypassed multi-factor authentication entirely. Stolen data included roughly 90 days of email history, exfiltrated using DNS tunneling and HTTP POST requests.

Why it succeeded

The attack succeeded partly because it broke the standard security assumption that phishing requires a click. Traditional awareness training focuses on avoiding suspicious links and attachments, but this campaign only required the target to view the email in a vulnerable webmail client.

The emails were also sent from a mix of compromised legitimate mailboxes and attacker-controlled Proton Mail addresses, which increased the odds recipients would treat them as trustworthy. Messages from a known coworker's account carry an inherent level of trust that attackers exploited directly.

What to watch for

  • Unexpected messages urging you to open or view them in webmail, even if no link or attachment is present
  • Sender addresses that seem slightly unusual, such as Proton Mail domains, even when the message content looks legitimate
  • Unfamiliar application-specific passwords or authentication tokens appearing on an email account
  • Signs of unusual outbound traffic patterns from mail servers, such as DNS tunneling

How to build resistance

Organizations using Zimbra or similar webmail platforms should prioritize fast patching of internet-facing email infrastructure, since attackers continue to exploit known vulnerabilities when systems remain unpatched. Security teams should also monitor mailbox configurations for unexpected application-specific passwords, since these can bypass MFA protections entirely.

Awareness efforts should be updated to reflect that previewing an email can carry risk on unpatched systems, not just clicking within it. Staff should be encouraged to report suspicious messages even when they only previewed them, and to treat unexpected messages from known coworkers with caution, since compromised internal mailboxes were used to distribute further exploit emails in this campaign.

Key findings

  • TA488 exploited Zimbra CVE-2025-66376 for at least five months using a “half-click” email workflow (open/preview triggers attack).
  • Victims did not need to click a link or open an attachment; the exploit executed JavaScript when the email was viewed in a vulnerable Zimbra client.
  • The ZimReaper malware harvested tokens/passwords/2FA recovery codes and created an app-specific password (“ZimbraWeb”) to maintain mailbox access while bypassing MFA.
  • Attack emails were sent from compromised accounts and attacker-controlled Proton Mail addresses to look legitimate.
  • Stolen data included roughly 90 days of email, with exfiltration observed via DNS tunneling and HTTP POST requests.

Who’s being targeted

  • Commonly targeted roles: All Zimbra webmail users, Government employees, Defense organization staff, Research/scientific staff, IT email administrators, Security operations / monitoring teams.
  • Affected industries: Government, Defense, Scientific/Research.
  • Attack channels: email.
  • Impersonated: A trusted internal sender (compromised mailbox) or a sender using a Proton Mail address to appear legitimate.

Red flags to watch for

  • Unexpected message that urges you to open it in webmail
  • Sender address may be unusual (e.g., Proton Mail) even if the email looks legitimate
  • Security training assumptions ("don’t click links") don’t apply; simply previewing is risky on unpatched systems
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What made the TA488 Zimbra attack a half-click attack?

Victims did not need to click a link or open an attachment. Simply opening or previewing the malicious email in a vulnerable Zimbra client was enough to execute JavaScript and trigger the exploit.

How did TA488 maintain access after compromising a mailbox?

The attackers created an application-specific password named ZimbraWeb, which gave persistent IMAP, POP3, and SMTP access to the mailbox while bypassing multi-factor authentication.

Who was targeted in this campaign?

The campaign focused on Ukrainian and U.S. government-related organizations, along with defense and scientific research groups, using Zimbra webmail.

How did the attackers make their emails look legitimate?

They sent exploit-laden emails from both compromised legitimate accounts and attacker-controlled Proton Mail addresses to increase the chance recipients would trust the messages.

Read the video transcript

You know that rule, "It's safe if you don't click"? TA488 just broke it for Zimbra webmail. A Russian-aligned group used a Zimbra flaw so that just opening or previewing that email ran hidden JavaScript, no link, no attachment, dropping ZimReaper to steal passwords and 2FA codes. Their emails came from real coworker accounts and Proton Mail addresses, then ZimReaper quietly added an app password called "ZimbraWeb" so they could keep reading 90 days of mail, even past MFA. If you see a weird "open in webmail" message or notice a mystery app password like "ZimbraWeb," stop and report it to security, even if you only previewed the email.

Similar attacks