Zero-Click Zimbra Webmail Phish Hits NATO Sectors

Unit 42 · High sophistication
Last updated July 30, 2026

Researchers at Unit 42 reported a real espionage campaign targeting organizations using Zimbra webmail, including government, defense, transportation and financial sectors. The attackers sent “zero-click” phishing emails disguised as news headlines, where opening/viewing the message could trigger a Zimbra vulnerability and silently steal mailbox data and credentials. The stolen data was sent to attacker-controlled command-and-control servers, with multiple domains and IPs observed.

How the attack worked

This campaign, tracked by Unit 42 as CL-STA-1114 and overlapping with a Russia-linked actor known as Void Blizzard or LAUNDRY BEAR, began with a phishing email disguised as a news digest. The message contained either an HTML attachment or embedded HTML in the body, styled around headlines such as a business and economics briefing, designed to catch the recipient's attention.

What made this campaign notable is that opening or viewing the message in Zimbra webmail could trigger CVE-2025-66376, a vulnerability in the Zimbra Collaboration Suite. The exploit automatically injected malicious JavaScript without requiring any click from the recipient, allowing the attackers to silently access mailbox data and credentials.

Why it succeeded

The lure itself was low-effort but effective because it mimicked something plausible and unremarkable: a routine news roundup. That reduced suspicion and did not require the recipient to click a link or download a file in the traditional sense. Because the exploit fired on viewing rather than on user action, normal phishing awareness cues, such as “don't click suspicious links,” did not fully apply here. Organizations running unpatched Zimbra instances were left exposed regardless of individual user caution.

What to watch for

  • Unexpected “news digest” or newsletter-style emails, especially those delivered as HTML attachments
  • Emails whose content is generic headlines seemingly designed to grab attention rather than convey specific relevant news
  • Unusual webmail or browser behavior after opening a message, even without clicking anything
  • Any indication of unauthorized mailbox access, such as unfamiliar sign-in activity

Building resistance

Because this attack could succeed without any click, technical controls matter as much as user awareness. Recommended steps include:

  • Prioritize patching of Zimbra Collaboration Suite instances against CVE-2025-66376
  • Encourage staff to report unexpected HTML attachments or unusual webmail behavior immediately, even absent an obvious phishing hook
  • Treat any suspected mailbox compromise as a serious incident, given that stolen data included passwords, 2FA scratch codes, and up to 90 days of email and search history
  • Extend awareness training to cover exploitation that requires no interaction, not just click-based phishing, so staff understand that vigilance alone cannot fully prevent this attack type

This technique aligns with MITRE ATT&CK entries for phishing (T1566.001), user execution of malicious files (T1204.002), scripting via JavaScript (T1059.007), and exfiltration over C2 channels (T1041), underscoring why layered defenses, not just user judgment, are essential against zero-click webmail exploitation.

Key findings

  • Unit 42 tracked a persistent cyberespionage campaign (CL-STA-1114) overlapping with a Russia-linked actor called Void Blizzard / LAUNDRY BEAR.
  • Targets included “Governments,” “Defense,” “Transportation,” and “Financial organizations” across NATO member states, Ukraine, CIS countries, and Africa.
  • Initial access used a phishing email with an HTML attachment or embedded HTML designed as news headlines.
  • The campaign used “zero-click phishing emails” exploiting “CVE-2025-66376” in Zimbra Collaboration Suite webmail to inject malicious JavaScript without user interaction.
  • Stolen data included “Email address and password,” “Two-factor authentication (2FA) scratch codes,” and “The victim’s last 90 days of email and search history.”
  • Unit 42 observed “at least nine IP addresses and nine domains for the C2 servers.”

Who’s being targeted

  • Commonly targeted roles: All staff using Zimbra webmail, Executives, Government employees, Defense personnel, Finance teams, IT / Email administrators, Security operations.
  • Affected industries: Government, Defense, Transportation, Financial services.
  • Attack channels: email.
  • Impersonated: News digest / media briefing sender.

Red flags to watch for

  • Unexpected HTML attachment or unusually formatted “newsletter” email
  • Content is generic headlines designed mainly to lure attention
  • Email causes unusual browser/webmail behavior despite no clicks (possible “zero-click” behavior)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What made this Zimbra phishing campaign zero-click?

The attackers exploited CVE-2025-66376 in the Zimbra Collaboration Suite webmail platform, which allowed malicious JavaScript to run automatically without any recipient interaction.

What data did the attackers steal?

Exfiltrated data included email addresses and passwords, two-factor authentication scratch codes, and the victim's last 90 days of email and search history.

Who was targeted in this campaign?

Targets included government, defense, transportation, and financial organizations across NATO member states, Ukraine, CIS countries, and Africa.

How was initial access gained?

Initial access started with a phishing email containing either an HTML attachment or embedded HTML designed as a news digest to catch recipients' attention.

Read the video transcript

Imagine just opening a Zimbra webmail message and losing your password, 2FA codes, and 90 days of email, without clicking anything. Unit 42 saw a real campaign, CL-STA-1114, targeting NATO sectors with a fake 'Global News Digest' HTML email that exploits CVE-2025-66376 in Zimbra to run malicious JavaScript as soon as it’s rendered. Behind that harmless-looking newsletter, the exploit can grab your email address and password, 2FA scratch codes, and your last 90 days of email and search history, then ship it off to multiple hidden C2 domains and IPs. If you see an unexpected Zimbra 'Global News Digest' or odd HTML newsletter that makes webmail act weird, stop and report it to Security immediately, assume it’s a zero-click incident, not just spam.

Similar attacks