
“No-Action” Emails Trigger OWA Mailbox Takeover
Russian-linked threat actors sent generic-looking informational emails that required no clicking, but simply opening them in vulnerable Outlook Web Access…
A Russian-aligned group (TA488) used malicious emails to exploit a Zimbra webmail flaw so that simply opening or previewing a message triggered compromise, no link click or attachment required. The attackers then stole email data and set up persistent access to compromised mail servers, including by creating an app password named “ZimbraWeb.” The campaign focused on Ukrainian and U.S. government-related organizations, plus defense and scientific groups.
TA488 exploited a Zimbra webmail vulnerability, CVE-2025-66376, for at least five months. What set this campaign apart is that victims did not need to click a link or open an attachment. Simply opening or previewing the malicious email in a vulnerable Zimbra client was enough to execute embedded JavaScript and trigger the exploit. This is often called a half-click attack because the only action required is viewing the message.
Once triggered, the ZimReaper malware harvested tokens, passwords, and 2FA recovery codes from the mailbox. Attackers also created an application-specific password named ZimbraWeb, giving them persistent IMAP, POP3, and SMTP access that bypassed multi-factor authentication entirely. Stolen data included roughly 90 days of email history, exfiltrated using DNS tunneling and HTTP POST requests.
The attack succeeded partly because it broke the standard security assumption that phishing requires a click. Traditional awareness training focuses on avoiding suspicious links and attachments, but this campaign only required the target to view the email in a vulnerable webmail client.
The emails were also sent from a mix of compromised legitimate mailboxes and attacker-controlled Proton Mail addresses, which increased the odds recipients would treat them as trustworthy. Messages from a known coworker's account carry an inherent level of trust that attackers exploited directly.
Organizations using Zimbra or similar webmail platforms should prioritize fast patching of internet-facing email infrastructure, since attackers continue to exploit known vulnerabilities when systems remain unpatched. Security teams should also monitor mailbox configurations for unexpected application-specific passwords, since these can bypass MFA protections entirely.
Awareness efforts should be updated to reflect that previewing an email can carry risk on unpatched systems, not just clicking within it. Staff should be encouraged to report suspicious messages even when they only previewed them, and to treat unexpected messages from known coworkers with caution, since compromised internal mailboxes were used to distribute further exploit emails in this campaign.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Victims did not need to click a link or open an attachment. Simply opening or previewing the malicious email in a vulnerable Zimbra client was enough to execute JavaScript and trigger the exploit.
The attackers created an application-specific password named ZimbraWeb, which gave persistent IMAP, POP3, and SMTP access to the mailbox while bypassing multi-factor authentication.
The campaign focused on Ukrainian and U.S. government-related organizations, along with defense and scientific research groups, using Zimbra webmail.
They sent exploit-laden emails from both compromised legitimate accounts and attacker-controlled Proton Mail addresses to increase the chance recipients would trust the messages.
You know that rule, "It's safe if you don't click"? TA488 just broke it for Zimbra webmail. A Russian-aligned group used a Zimbra flaw so that just opening or previewing that email ran hidden JavaScript, no link, no attachment, dropping ZimReaper to steal passwords and 2FA codes. Their emails came from real coworker accounts and Proton Mail addresses, then ZimReaper quietly added an app password called "ZimbraWeb" so they could keep reading 90 days of mail, even past MFA. If you see a weird "open in webmail" message or notice a mystery app password like "ZimbraWeb," stop and report it to security, even if you only previewed the email.

Russian-linked threat actors sent generic-looking informational emails that required no clicking, but simply opening them in vulnerable Outlook Web Access…

A Russia-aligned espionage group sent specially crafted HTML emails that could compromise vulnerable Zimbra webmail servers just by being opened or previewed,…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

Kaspersky reports an active malware campaign (“OkoBot”) that tricks people into running malicious scripts via a ClickFix-style prompt or by downloading a fake…

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into…

Scammers are posing as FBI staff who supposedly handle IC3 (Internet Crime Complaint Center) reports to trick people who have already been scammed once. The…