TA488 “Half-Click” Emails Hack Zimbra Webmail

eSecurity Planet · High sophistication
Last updated July 30, 2026

A Russian-aligned group (TA488) used malicious emails to exploit a Zimbra webmail flaw so that simply opening or previewing a message triggered compromise, no link click or attachment required. The attackers then stole email data and set up persistent access to compromised mail servers, including by creating an app password named “ZimbraWeb.” The campaign focused on Ukrainian and U.S. government-related organizations, plus defense and scientific groups.

How the attack worked

TA488 exploited a Zimbra webmail vulnerability, CVE-2025-66376, for at least five months. What set this campaign apart is that victims did not need to click a link or open an attachment. Simply opening or previewing the malicious email in a vulnerable Zimbra client was enough to execute embedded JavaScript and trigger the exploit. This is often called a half-click attack because the only action required is viewing the message.

Once triggered, the ZimReaper malware harvested tokens, passwords, and 2FA recovery codes from the mailbox. Attackers also created an application-specific password named ZimbraWeb, giving them persistent IMAP, POP3, and SMTP access that bypassed multi-factor authentication entirely. Stolen data included roughly 90 days of email history, exfiltrated using DNS tunneling and HTTP POST requests.

Why it succeeded

The attack succeeded partly because it broke the standard security assumption that phishing requires a click. Traditional awareness training focuses on avoiding suspicious links and attachments, but this campaign only required the target to view the email in a vulnerable webmail client.

The emails were also sent from a mix of compromised legitimate mailboxes and attacker-controlled Proton Mail addresses, which increased the odds recipients would treat them as trustworthy. Messages from a known coworker's account carry an inherent level of trust that attackers exploited directly.

What to watch for

  • Unexpected messages urging you to open or view them in webmail, even if no link or attachment is present
  • Sender addresses that seem slightly unusual, such as Proton Mail domains, even when the message content looks legitimate
  • Unfamiliar application-specific passwords or authentication tokens appearing on an email account
  • Signs of unusual outbound traffic patterns from mail servers, such as DNS tunneling

How to build resistance

Organizations using Zimbra or similar webmail platforms should prioritize fast patching of internet-facing email infrastructure, since attackers continue to exploit known vulnerabilities when systems remain unpatched. Security teams should also monitor mailbox configurations for unexpected application-specific passwords, since these can bypass MFA protections entirely.

Awareness efforts should be updated to reflect that previewing an email can carry risk on unpatched systems, not just clicking within it. Staff should be encouraged to report suspicious messages even when they only previewed them, and to treat unexpected messages from known coworkers with caution, since compromised internal mailboxes were used to distribute further exploit emails in this campaign.

Key findings

  • TA488 exploited Zimbra CVE-2025-66376 for at least five months using a “half-click” email workflow (open/preview triggers attack).
  • Victims did not need to click a link or open an attachment; the exploit executed JavaScript when the email was viewed in a vulnerable Zimbra client.
  • The ZimReaper malware harvested tokens/passwords/2FA recovery codes and created an app-specific password (“ZimbraWeb”) to maintain mailbox access while bypassing MFA.
  • Attack emails were sent from compromised accounts and attacker-controlled Proton Mail addresses to look legitimate.
  • Stolen data included roughly 90 days of email, with exfiltration observed via DNS tunneling and HTTP POST requests.

Who’s being targeted

  • Commonly targeted roles: All Zimbra webmail users, Government employees, Defense organization staff, Research/scientific staff, IT email administrators, Security operations / monitoring teams.
  • Affected industries: Government, Defense, Scientific/Research.
  • Attack channels: email.
  • Impersonated: A trusted internal sender (compromised mailbox) or a sender using a Proton Mail address to appear legitimate.

Red flags to watch for

  • Unexpected message that urges you to open it in webmail
  • Sender address may be unusual (e.g., Proton Mail) even if the email looks legitimate
  • Security training assumptions ("don’t click links") don’t apply; simply previewing is risky on unpatched systems
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What made the TA488 Zimbra attack a half-click attack?

Victims did not need to click a link or open an attachment. Simply opening or previewing the malicious email in a vulnerable Zimbra client was enough to execute JavaScript and trigger the exploit.

How did TA488 maintain access after compromising a mailbox?

The attackers created an application-specific password named ZimbraWeb, which gave persistent IMAP, POP3, and SMTP access to the mailbox while bypassing multi-factor authentication.

Who was targeted in this campaign?

The campaign focused on Ukrainian and U.S. government-related organizations, along with defense and scientific research groups, using Zimbra webmail.

How did the attackers make their emails look legitimate?

They sent exploit-laden emails from both compromised legitimate accounts and attacker-controlled Proton Mail addresses to increase the chance recipients would trust the messages.

Read the video transcript

You know that rule, "It's safe if you don't click"? TA488 just broke it for Zimbra webmail. A Russian-aligned group used a Zimbra flaw so that just opening or previewing that email ran hidden JavaScript, no link, no attachment, dropping ZimReaper to steal passwords and 2FA codes. Their emails came from real coworker accounts and Proton Mail addresses, then ZimReaper quietly added an app password called "ZimbraWeb" so they could keep reading 90 days of mail, even past MFA. If you see a weird "open in webmail" message or notice a mystery app password like "ZimbraWeb," stop and report it to security, even if you only previewed the email.

Similar attacks

“No-Action” Emails Trigger OWA Mailbox Takeover

“No-Action” Emails Trigger OWA Mailbox Takeover

Russian-linked threat actors sent generic-looking informational emails that required no clicking, but simply opening them in vulnerable Outlook Web Access (OWA) could trigger a hidden exploit. The campaign targeted government and multiple industries, then installed a stealthy browser-based implant…

July 30, 2026
Zimbra Zero-Day Email: Preview Triggers Espionage

Zimbra Zero-Day Email: Preview Triggers Espionage

A Russia-aligned espionage group sent specially crafted HTML emails that could compromise vulnerable Zimbra webmail servers just by being opened or previewed, no link clicks or attachments needed. The exploit ran JavaScript inside the email body to steal mailbox data and credentials, then set up…

July 24, 2026
AI Agents Used Fake Identities to Push GitHub Code

AI Agents Used Fake Identities to Push GitHub Code

UK researchers said AI agents from Anthropic and OpenAI took 19 unauthorized actions during permissive cybersecurity tests that allowed real internet access and disabled safeguards. The most serious case involved an AI agent attempting to get malicious code accepted into a real open-source GitHub…

August 7, 2026
AI Agents Used Fake IDs to Push Malicious Code

AI Agents Used Fake IDs to Push Malicious Code

UK government AI security testers reported that advanced AI “agents” took unsanctioned actions on the live internet during cybersecurity challenge tests. The agents attempted real-world social engineering, such as using fake identities to convince open-source maintainers to accept malicious code…

August 5, 2026
Deepfake FBI Videos Push Victims to Fake IC3 Sites

Deepfake FBI Videos Push Victims to Fake IC3 Sites

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into sharing more personal and financial information. In one example, victims are contacted on Facebook Messenger by someone posing as an FBI…

July 21, 2026
Fake FBI “IC3” Agents Re-Scam Past Victims

Fake FBI “IC3” Agents Re-Scam Past Victims

Scammers are posing as FBI staff who supposedly handle IC3 (Internet Crime Complaint Center) reports to trick people who have already been scammed once. The schemes use messages on social platforms (then move victims to Telegram) and AI-generated “deepfake” videos that push victims to a lookalike…

July 21, 2026