Zimbra Email View Triggers Russian Data Theft

The Register Security · High sophistication
Last updated July 30, 2026

Government agencies say a Russian-linked group sent specially crafted HTML emails that exploit a Zimbra webmail flaw, so simply viewing the message can trigger data theft, no click required. The campaign has targeted multiple Western sectors since July 2025 and focuses on stealing email content and login information to maintain access.

How the attack worked

A Russian-linked group tracked as Laundry Bear, also known as Void Blizzard, sent specially crafted HTML emails that exploit a cross-site scripting flaw in Zimbra webmail, tracked as CVE-2025-66376. Unlike most phishing, this campaign did not depend on the victim clicking a link or opening an attachment. Simply viewing the email in a vulnerable Zimbra client was enough to trigger malicious code execution. Once triggered, the attackers focused on covertly acquiring email data and used stolen credentials to maintain access, modifying account preferences and creating new application passcodes to keep their foothold.

Why it succeeded

This attack succeeded because it removed the usual human decision point that awareness training targets. Most phishing defenses teach people to scrutinize links, sender addresses, and attachments before acting. Here, the exploit fired the moment the email was rendered for viewing, meaning caution about clicking provided no protection. The campaign also relied on an unpatched software vulnerability rather than solely on deception, combining a technical flaw with the routine act of checking email, something nearly every employee does many times a day without a second thought.

What to watch for

  • Unexpected HTML emails from unfamiliar senders, even without links or attachments
  • Signs of account compromise after opening a suspicious message, such as unexplained changes to email account preferences
  • Newly created application passcodes that were not requested by the account owner
  • Unusual activity tied to two-factor authentication tokens or global address list access
  • Use of an unpatched Zimbra webmail client in an organization that has not yet applied available updates

How to build resistance

Because this attack required no user interaction beyond viewing a message, technical controls and rapid patching matter as much as awareness. Organizations should prioritize applying the Zimbra patch and, where advised by security teams, temporarily limit use of the affected webmail client. Staff across all roles, not just IT and email administrators, should still be encouraged to report unexpected or unusual emails, since early reporting can help security operations identify a campaign before it spreads further. Helpdesk and IT teams should also actively monitor for the account-level indicators described above, since these can reveal compromise even when the initial email itself looked unremarkable. Given the broad range of affected sectors, including defense, government, education, energy, law enforcement, media, and NGOs, this type of zero-click email threat is relevant to nearly any organization relying on webmail platforms.

Key findings

  • A Russian-linked group (Laundry Bear/Void Blizzard) used HTML emails to exploit a Zimbra webmail XSS vulnerability (CVE-2025-66376).
  • The attack triggers when the victim views the email, “no need to even click on a link or open a file.”
  • Targets span defense industry, government, education, energy, law enforcement, media, NGOs, and technology sectors.
  • Stolen data reportedly includes 90 days of emails, passwords, global address lists, 2FA tokens, and application passcodes.
  • Attackers used stolen credentials to maintain access and modified email account preferences.
  • Agencies recommend limiting use of Zimbra webmail until patched; the joint alert includes extensive IOCs.

Who’s being targeted

  • Commonly targeted roles: All staff who use webmail, Executives and assistants, IT/Email administrators, Security operations, Helpdesk.
  • Affected industries: Defense industrial base, Federal government, Local government, Education, Energy, Law enforcement, Media, Non-governmental organizations (NGOs), Technology.
  • Attack channels: email.
  • Impersonated: Unknown sender (not specified in article).

Red flags to watch for

  • Unexpected HTML email from an unfamiliar sender
  • Using an unpatched Zimbra webmail client vulnerable to CVE-2025-66376
  • Email viewing alone causing unusual account activity (preference changes, new app passcodes)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

Do I need to click a link for this Zimbra attack to work?

No. According to the joint alert, the attack triggers as soon as the victim views the malicious HTML email in Zimbra webmail, with no need to click a link or open a file.

What data does this attack steal?

Reported stolen data includes up to 90 days of emails, passwords, global address lists, two-factor authentication tokens, and application passcodes.

Who is being targeted?

The campaign has targeted organizations across defense, government, education, energy, law enforcement, media, NGOs, and technology sectors since July 2025.

What should organizations do about this Zimbra vulnerability?

Agencies recommend limiting use of the Zimbra webmail client until organizations apply the available patch, and monitoring for signs of account takeover such as changed preferences or newly created app passcodes.

Read the video transcript

Imagine this: you just open your inbox, glance at an email, and boom, your account’s already compromised. That’s the Zimbra webmail bug, CVE-2025-66376. Laundry Bear, also called Void Blizzard, sent malware-laden HTML emails that exploit a Zimbra XSS flaw. Just viewing the message in Zimbra can silently dump 90 days of your email, passwords, 2FA tokens, and app passcodes. Here’s the nasty part: there might be no link, no attachment, nothing obvious. The only clue is the context, an unexpected HTML email in Zimbra, and then weird account behavior: settings changed, new app passwords, logins you don’t recognize. If you use Zimbra and see a weird HTML email or odd changes in your mailbox, don’t ignore it, hit the phishing or report button and call IT. Let them know, "This might be that Zimbra CVE-2025-66376 thing."

Similar attacks