
“TTF Trap” Uses Fake Font Files to Drop Malware
FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive…
Researchers at Unit 42 reported a real espionage campaign targeting organizations using Zimbra webmail, including government, defense, transportation and financial sectors. The attackers sent “zero-click” phishing emails disguised as news headlines, where opening/viewing the message could trigger a Zimbra vulnerability and silently steal mailbox data and credentials. The stolen data was sent to attacker-controlled command-and-control servers, with multiple domains and IPs observed.
This campaign, tracked by Unit 42 as CL-STA-1114 and overlapping with a Russia-linked actor known as Void Blizzard or LAUNDRY BEAR, began with a phishing email disguised as a news digest. The message contained either an HTML attachment or embedded HTML in the body, styled around headlines such as a business and economics briefing, designed to catch the recipient's attention.
What made this campaign notable is that opening or viewing the message in Zimbra webmail could trigger CVE-2025-66376, a vulnerability in the Zimbra Collaboration Suite. The exploit automatically injected malicious JavaScript without requiring any click from the recipient, allowing the attackers to silently access mailbox data and credentials.
The lure itself was low-effort but effective because it mimicked something plausible and unremarkable: a routine news roundup. That reduced suspicion and did not require the recipient to click a link or download a file in the traditional sense. Because the exploit fired on viewing rather than on user action, normal phishing awareness cues, such as “don't click suspicious links,” did not fully apply here. Organizations running unpatched Zimbra instances were left exposed regardless of individual user caution.
Because this attack could succeed without any click, technical controls matter as much as user awareness. Recommended steps include:
This technique aligns with MITRE ATT&CK entries for phishing (T1566.001), user execution of malicious files (T1204.002), scripting via JavaScript (T1059.007), and exfiltration over C2 channels (T1041), underscoring why layered defenses, not just user judgment, are essential against zero-click webmail exploitation.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
The attackers exploited CVE-2025-66376 in the Zimbra Collaboration Suite webmail platform, which allowed malicious JavaScript to run automatically without any recipient interaction.
Exfiltrated data included email addresses and passwords, two-factor authentication scratch codes, and the victim's last 90 days of email and search history.
Targets included government, defense, transportation, and financial organizations across NATO member states, Ukraine, CIS countries, and Africa.
Initial access started with a phishing email containing either an HTML attachment or embedded HTML designed as a news digest to catch recipients' attention.
Imagine just opening a Zimbra webmail message and losing your password, 2FA codes, and 90 days of email, without clicking anything. Unit 42 saw a real campaign, CL-STA-1114, targeting NATO sectors with a fake 'Global News Digest' HTML email that exploits CVE-2025-66376 in Zimbra to run malicious JavaScript as soon as it’s rendered. Behind that harmless-looking newsletter, the exploit can grab your email address and password, 2FA scratch codes, and your last 90 days of email and search history, then ship it off to multiple hidden C2 domains and IPs. If you see an unexpected Zimbra 'Global News Digest' or odd HTML newsletter that makes webmail act weird, stop and report it to Security immediately, assume it’s a zero-click incident, not just spam.

FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive…

Researchers report a real, ongoing phishing campaign where attackers impersonate well-known companies and send business or payment-themed emails that trick…

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude…

A real phishing campaign targeted Indian businesses and individual taxpayers by impersonating government departments and sending emails that look like official…

Kaspersky reports an active malware campaign (“OkoBot”) that tricks people into running malicious scripts via a ClickFix-style prompt or by downloading a fake…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…