Zero-Click Emails Hit Zimbra Users in Espionage Push

The Record · High sophistication
Last updated July 30, 2026

Government agencies and security firms warn that Russia-aligned hackers are using “zero-click” phishing emails to compromise organizations using Zimbra webmail. The attack hides a malicious JavaScript payload inside an email so it runs when the message is opened, aiming to steal recent email, passwords, contacts, and authentication tokens. Authorities urge Zimbra customers to patch immediately or switch users to a different mail client if patching isn’t possible.

How the attack worked

This campaign relies on a hidden JavaScript payload embedded inside routine-looking emails. Rather than asking a victim to click a link or open an attachment, the payload is executed immediately when the emails are opened in Zimbra webmail. That means the simple act of reading a message in the web interface is enough to trigger compromise.

What makes the pretext especially convincing is that the emails come from previously compromised email accounts. Victims are not looking at a spoofed sender or an unfamiliar name, they are seeing a message that appears to come from someone they already know and trust.

Why it succeeded

Traditional phishing awareness training teaches people to scrutinize links and attachments before acting. This attack sidesteps that entire mental model. There is no suspicious link to hover over and no attachment to think twice about, just an email that looks routine and a webmail client that renders the hidden script automatically.

The use of real, previously compromised accounts as the delivery mechanism also removes one of the most reliable red flags defenders rely on, an unfamiliar or spoofed sender address.

What to watch for

  • Unexpected emails, even from contacts you recognize, since their accounts may have been compromised and used to reach you
  • Any unusual behavior after opening an email in Zimbra webmail, including unexpected session prompts, redirects, or signs of mailbox access you did not initiate
  • Unexplained changes to mail forwarding rules or authentication settings
  • Reliance on the Zimbra web interface specifically, since that is the platform this campaign targets

Post-compromise, the objective is broad: attackers have attempted to pull the last 90 days of emails, stored passwords, contact lists, and two-factor authentication tokens and other passcodes, so any sign of unusual mailbox activity deserves quick attention.

Building resistance

Because this attack does not depend on a user clicking anything, the most effective defenses are technical and procedural rather than purely behavioral:

  • Patch Zimbra webmail software immediately wherever it is deployed
  • Where patching is not immediately feasible, move affected users to a different mail client until it can be applied
  • Reinforce with staff that opening an email is not automatically "safe," even without clicking further
  • Extend awareness training to cover account compromise scenarios, since a message from a known contact is no longer a reliable trust signal on its own
  • Monitor for anomalous mailbox access, unexpected authentication prompts, or unusual token or passcode requests tied to webmail sessions

Government, defense, transportation, and finance organizations are among those named as targets, reflecting the broad reach of this campaign across sectors that rely heavily on email-based communication and collaboration tools.

Key findings

  • Russia-aligned threat actor Laundry Bear is accused of compromising Western government and commercial organizations via “zero-click phishing emails” targeting Zimbra webmail.
  • The campaign exploits CVE-2025-66376 (patched in November 2025) using a “malicious JavaScript payload” hidden in emails sent from previously compromised accounts.
  • The payload “is executed immediately when the emails are opened,” meaning victims may be compromised without clicking a link or opening an attachment.
  • Post-compromise objectives include stealing “the last 90 days of emails,” “passwords,” “contact lists,” and “two-factor authentication tokens and other passcodes.”
  • Targets span government, defense, transportation, and financial organizations across NATO states, Ukraine, CIS countries, and Africa.

Who’s being targeted

  • Commonly targeted roles: Government employees, Defense and defense industrial base, Transportation sector staff, Finance teams, IT administrators managing Zimbra, Security operations and incident response.
  • Affected industries: Government, Defense, Transportation, Finance, Maritime.
  • Attack channels: email.
  • Impersonated: A real (previously compromised) email account/contact, A legitimate sender within the victim’s ecosystem (compromised account).

Red flags to watch for

  • Unexpected email even though it appears to come from a real contact (account may be compromised)
  • Using Zimbra webmail to read the message is enough to trigger the attack (no click needed)
  • Unusual behavior after opening an email (session prompts, strange redirects, or mailbox access anomalies)
  • Employees using the Zimbra web interface are at higher risk until patches are applied
  • Signs of mailbox access or forwarding rules changes without user action
  • Unexpected prompts related to sign-in, sessions, or authentication tokens
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What makes this Zimbra phishing attack zero-click?

The malicious JavaScript payload is hidden inside the email itself and executes immediately when the message is opened in Zimbra webmail, so no link click or attachment download is required.

What data are attackers trying to steal?

According to the advisory, the campaign attempts to exfiltrate the last 90 days of emails, passwords, contact lists, and two-factor authentication tokens and other passcodes.

How are the phishing emails delivered?

The payload is hidden in emails sent from previously compromised email accounts, making the messages appear to come from real, trusted contacts.

What should Zimbra users do to protect themselves?

Government agencies urged organizations to immediately patch Zimbra software and, if patching is not feasible, to direct employees to use a different mail client until they can.

Read the video transcript

You open a routine email in Zimbra webmail, no link, no attachment… and you’re already hacked. Russia‑aligned group Laundry Bear is using a Zimbra zero‑click exploit, CVE‑2025‑66376. A malicious JavaScript payload hidden in that email runs the moment you open it. From there, they quietly grab your last 90 days of email, passwords, contact lists, even two‑factor authentication tokens, and can spread from your compromised account to colleagues. Aha moment: not clicking isn’t enough. If you use Zimbra, assume zero‑click is real, ask IT now if Zimbra is patched or if you should switch off webmail.

Similar attacks

“Half-Click” OWA Email Trap Spreads

“Half-Click” OWA Email Trap Spreads

Proofpoint reports a Russian-linked espionage group is using booby-trapped emails that infect users simply when they open the message in Outlook Web Access…

July 30, 2026