
“No-Action” Emails Trigger OWA Mailbox Takeover
Russian-linked threat actors sent generic-looking informational emails that required no clicking, but simply opening them in vulnerable Outlook Web Access…
Government agencies and security firms warn that Russia-aligned hackers are using “zero-click” phishing emails to compromise organizations using Zimbra webmail. The attack hides a malicious JavaScript payload inside an email so it runs when the message is opened, aiming to steal recent email, passwords, contacts, and authentication tokens. Authorities urge Zimbra customers to patch immediately or switch users to a different mail client if patching isn’t possible.
This campaign relies on a hidden JavaScript payload embedded inside routine-looking emails. Rather than asking a victim to click a link or open an attachment, the payload is executed immediately when the emails are opened in Zimbra webmail. That means the simple act of reading a message in the web interface is enough to trigger compromise.
What makes the pretext especially convincing is that the emails come from previously compromised email accounts. Victims are not looking at a spoofed sender or an unfamiliar name, they are seeing a message that appears to come from someone they already know and trust.
Traditional phishing awareness training teaches people to scrutinize links and attachments before acting. This attack sidesteps that entire mental model. There is no suspicious link to hover over and no attachment to think twice about, just an email that looks routine and a webmail client that renders the hidden script automatically.
The use of real, previously compromised accounts as the delivery mechanism also removes one of the most reliable red flags defenders rely on, an unfamiliar or spoofed sender address.
Post-compromise, the objective is broad: attackers have attempted to pull the last 90 days of emails, stored passwords, contact lists, and two-factor authentication tokens and other passcodes, so any sign of unusual mailbox activity deserves quick attention.
Because this attack does not depend on a user clicking anything, the most effective defenses are technical and procedural rather than purely behavioral:
Government, defense, transportation, and finance organizations are among those named as targets, reflecting the broad reach of this campaign across sectors that rely heavily on email-based communication and collaboration tools.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
The malicious JavaScript payload is hidden inside the email itself and executes immediately when the message is opened in Zimbra webmail, so no link click or attachment download is required.
According to the advisory, the campaign attempts to exfiltrate the last 90 days of emails, passwords, contact lists, and two-factor authentication tokens and other passcodes.
The payload is hidden in emails sent from previously compromised email accounts, making the messages appear to come from real, trusted contacts.
Government agencies urged organizations to immediately patch Zimbra software and, if patching is not feasible, to direct employees to use a different mail client until they can.
You open a routine email in Zimbra webmail, no link, no attachment… and you’re already hacked. Russia‑aligned group Laundry Bear is using a Zimbra zero‑click exploit, CVE‑2025‑66376. A malicious JavaScript payload hidden in that email runs the moment you open it. From there, they quietly grab your last 90 days of email, passwords, contact lists, even two‑factor authentication tokens, and can spread from your compromised account to colleagues. Aha moment: not clicking isn’t enough. If you use Zimbra, assume zero‑click is real, ask IT now if Zimbra is patched or if you should switch off webmail.

Russian-linked threat actors sent generic-looking informational emails that required no clicking, but simply opening them in vulnerable Outlook Web Access…

UK and US cyber authorities and Proofpoint reported a real campaign where the Russian-linked group “Laundry Bear” (TA488) sent emails that could infect victims…

South Korean agencies and AhnLab warn that tools tied to North Korea’s Lazarus Group appear to be shared with the Gunra ransomware operation targeting South…

Proofpoint reports a Russian-linked espionage group is using booby-trapped emails that infect users simply when they open the message in Outlook Web Access…

Researchers at Unit 42 reported a real espionage campaign targeting organizations using Zimbra webmail, including government, defense, transportation and…

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude…