Zero-Click Zimbra Webmail Phish Hits NATO Sectors

Unit 42 · High sophistication
Last updated July 30, 2026

Researchers at Unit 42 reported a real espionage campaign targeting organizations using Zimbra webmail, including government, defense, transportation and financial sectors. The attackers sent “zero-click” phishing emails disguised as news headlines, where opening/viewing the message could trigger a Zimbra vulnerability and silently steal mailbox data and credentials. The stolen data was sent to attacker-controlled command-and-control servers, with multiple domains and IPs observed.

How the attack worked

This campaign, tracked by Unit 42 as CL-STA-1114 and overlapping with a Russia-linked actor known as Void Blizzard or LAUNDRY BEAR, began with a phishing email disguised as a news digest. The message contained either an HTML attachment or embedded HTML in the body, styled around headlines such as a business and economics briefing, designed to catch the recipient's attention.

What made this campaign notable is that opening or viewing the message in Zimbra webmail could trigger CVE-2025-66376, a vulnerability in the Zimbra Collaboration Suite. The exploit automatically injected malicious JavaScript without requiring any click from the recipient, allowing the attackers to silently access mailbox data and credentials.

Why it succeeded

The lure itself was low-effort but effective because it mimicked something plausible and unremarkable: a routine news roundup. That reduced suspicion and did not require the recipient to click a link or download a file in the traditional sense. Because the exploit fired on viewing rather than on user action, normal phishing awareness cues, such as “don't click suspicious links,” did not fully apply here. Organizations running unpatched Zimbra instances were left exposed regardless of individual user caution.

What to watch for

  • Unexpected “news digest” or newsletter-style emails, especially those delivered as HTML attachments
  • Emails whose content is generic headlines seemingly designed to grab attention rather than convey specific relevant news
  • Unusual webmail or browser behavior after opening a message, even without clicking anything
  • Any indication of unauthorized mailbox access, such as unfamiliar sign-in activity

Building resistance

Because this attack could succeed without any click, technical controls matter as much as user awareness. Recommended steps include:

  • Prioritize patching of Zimbra Collaboration Suite instances against CVE-2025-66376
  • Encourage staff to report unexpected HTML attachments or unusual webmail behavior immediately, even absent an obvious phishing hook
  • Treat any suspected mailbox compromise as a serious incident, given that stolen data included passwords, 2FA scratch codes, and up to 90 days of email and search history
  • Extend awareness training to cover exploitation that requires no interaction, not just click-based phishing, so staff understand that vigilance alone cannot fully prevent this attack type

This technique aligns with MITRE ATT&CK entries for phishing (T1566.001), user execution of malicious files (T1204.002), scripting via JavaScript (T1059.007), and exfiltration over C2 channels (T1041), underscoring why layered defenses, not just user judgment, are essential against zero-click webmail exploitation.

Key findings

  • Unit 42 tracked a persistent cyberespionage campaign (CL-STA-1114) overlapping with a Russia-linked actor called Void Blizzard / LAUNDRY BEAR.
  • Targets included “Governments,” “Defense,” “Transportation,” and “Financial organizations” across NATO member states, Ukraine, CIS countries, and Africa.
  • Initial access used a phishing email with an HTML attachment or embedded HTML designed as news headlines.
  • The campaign used “zero-click phishing emails” exploiting “CVE-2025-66376” in Zimbra Collaboration Suite webmail to inject malicious JavaScript without user interaction.
  • Stolen data included “Email address and password,” “Two-factor authentication (2FA) scratch codes,” and “The victim’s last 90 days of email and search history.”
  • Unit 42 observed “at least nine IP addresses and nine domains for the C2 servers.”

Who’s being targeted

  • Commonly targeted roles: All staff using Zimbra webmail, Executives, Government employees, Defense personnel, Finance teams, IT / Email administrators, Security operations.
  • Affected industries: Government, Defense, Transportation, Financial services.
  • Attack channels: email.
  • Impersonated: News digest / media briefing sender.

Red flags to watch for

  • Unexpected HTML attachment or unusually formatted “newsletter” email
  • Content is generic headlines designed mainly to lure attention
  • Email causes unusual browser/webmail behavior despite no clicks (possible “zero-click” behavior)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What made this Zimbra phishing campaign zero-click?

The attackers exploited CVE-2025-66376 in the Zimbra Collaboration Suite webmail platform, which allowed malicious JavaScript to run automatically without any recipient interaction.

What data did the attackers steal?

Exfiltrated data included email addresses and passwords, two-factor authentication scratch codes, and the victim's last 90 days of email and search history.

Who was targeted in this campaign?

Targets included government, defense, transportation, and financial organizations across NATO member states, Ukraine, CIS countries, and Africa.

How was initial access gained?

Initial access started with a phishing email containing either an HTML attachment or embedded HTML designed as a news digest to catch recipients' attention.

Read the video transcript

Imagine just opening a Zimbra webmail message and losing your password, 2FA codes, and 90 days of email, without clicking anything. Unit 42 saw a real campaign, CL-STA-1114, targeting NATO sectors with a fake 'Global News Digest' HTML email that exploits CVE-2025-66376 in Zimbra to run malicious JavaScript as soon as it’s rendered. Behind that harmless-looking newsletter, the exploit can grab your email address and password, 2FA scratch codes, and your last 90 days of email and search history, then ship it off to multiple hidden C2 domains and IPs. If you see an unexpected Zimbra 'Global News Digest' or odd HTML newsletter that makes webmail act weird, stop and report it to Security immediately, assume it’s a zero-click incident, not just spam.

Similar attacks

Resume Phish Hit Brazil Banks; AI Aided Ops

Resume Phish Hit Brazil Banks; AI Aided Ops

Two real, ongoing intrusion campaigns targeted organizations in Latin America, including a Mexican transportation organization and Brazil’s financial sector. In the Brazil campaign, attackers reportedly got in via a resume-themed phishing attachment, then attempted to download and run tunneling…

September 3, 2026
“TTF Trap” Uses Fake Font Files to Drop Malware

“TTF Trap” Uses Fake Font Files to Drop Malware

FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive that ultimately runs malware on Windows. The trick is a file ending in .ttf (TrueType font) that is actually a malicious script executed by…

July 17, 2026
APT28 Uses Diplomatic Word Lures to Drop HOOKEDGE

APT28 Uses Diplomatic Word Lures to Drop HOOKEDGE

Researchers report real-world campaigns targeting European government and diplomatic organizations using diplomatic-themed Microsoft Word documents. Victims are prompted to click “Enable Content,” which runs malicious macros that install the HOOKEDGE backdoor and connect to webhook-based…

August 28, 2026
Spark RAT Phish Hits Cambodia With “Official” Lures

Spark RAT Phish Hits Cambodia With “Official” Lures

A real campaign targeting people and organizations in Cambodia uses phishing emails with localized “official-looking” themes to trick recipients into running an installer from a compressed file. Once executed, the malware chain deploys Spark RAT for remote control and uses a vulnerable OPSWAT…

August 27, 2026
Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Researchers say the North Korea-linked Lazarus group ran “Operation Dream Job,” posing as recruiters and sending fake job offers to lure targets into downloading trojanized PDF tools and opening booby-trapped PDFs. The campaign focused largely on defense-related organizations and used both a…

August 12, 2026
Lazarus “Dream Job” Lures Spread Zero-Day Attack

Lazarus “Dream Job” Lures Spread Zero-Day Attack

Check Point and Microsoft report North Korea’s Lazarus Group used a long-running “Dream Job” social engineering campaign to target defense-sector job seekers with fake employer sites and trojanized documents/software. Victims were lured into opening malicious PDFs or installing a modified PDF…

August 11, 2026