Zimbra Email View Triggers Russian Data Theft

The Register Security · High sophistication
Last updated July 30, 2026

Government agencies say a Russian-linked group sent specially crafted HTML emails that exploit a Zimbra webmail flaw, so simply viewing the message can trigger data theft, no click required. The campaign has targeted multiple Western sectors since July 2025 and focuses on stealing email content and login information to maintain access.

How the attack worked

A Russian-linked group tracked as Laundry Bear, also known as Void Blizzard, sent specially crafted HTML emails that exploit a cross-site scripting flaw in Zimbra webmail, tracked as CVE-2025-66376. Unlike most phishing, this campaign did not depend on the victim clicking a link or opening an attachment. Simply viewing the email in a vulnerable Zimbra client was enough to trigger malicious code execution. Once triggered, the attackers focused on covertly acquiring email data and used stolen credentials to maintain access, modifying account preferences and creating new application passcodes to keep their foothold.

Why it succeeded

This attack succeeded because it removed the usual human decision point that awareness training targets. Most phishing defenses teach people to scrutinize links, sender addresses, and attachments before acting. Here, the exploit fired the moment the email was rendered for viewing, meaning caution about clicking provided no protection. The campaign also relied on an unpatched software vulnerability rather than solely on deception, combining a technical flaw with the routine act of checking email, something nearly every employee does many times a day without a second thought.

What to watch for

  • Unexpected HTML emails from unfamiliar senders, even without links or attachments
  • Signs of account compromise after opening a suspicious message, such as unexplained changes to email account preferences
  • Newly created application passcodes that were not requested by the account owner
  • Unusual activity tied to two-factor authentication tokens or global address list access
  • Use of an unpatched Zimbra webmail client in an organization that has not yet applied available updates

How to build resistance

Because this attack required no user interaction beyond viewing a message, technical controls and rapid patching matter as much as awareness. Organizations should prioritize applying the Zimbra patch and, where advised by security teams, temporarily limit use of the affected webmail client. Staff across all roles, not just IT and email administrators, should still be encouraged to report unexpected or unusual emails, since early reporting can help security operations identify a campaign before it spreads further. Helpdesk and IT teams should also actively monitor for the account-level indicators described above, since these can reveal compromise even when the initial email itself looked unremarkable. Given the broad range of affected sectors, including defense, government, education, energy, law enforcement, media, and NGOs, this type of zero-click email threat is relevant to nearly any organization relying on webmail platforms.

Key findings

  • A Russian-linked group (Laundry Bear/Void Blizzard) used HTML emails to exploit a Zimbra webmail XSS vulnerability (CVE-2025-66376).
  • The attack triggers when the victim views the email, “no need to even click on a link or open a file.”
  • Targets span defense industry, government, education, energy, law enforcement, media, NGOs, and technology sectors.
  • Stolen data reportedly includes 90 days of emails, passwords, global address lists, 2FA tokens, and application passcodes.
  • Attackers used stolen credentials to maintain access and modified email account preferences.
  • Agencies recommend limiting use of Zimbra webmail until patched; the joint alert includes extensive IOCs.

Who’s being targeted

  • Commonly targeted roles: All staff who use webmail, Executives and assistants, IT/Email administrators, Security operations, Helpdesk.
  • Affected industries: Defense industrial base, Federal government, Local government, Education, Energy, Law enforcement, Media, Non-governmental organizations (NGOs), Technology.
  • Attack channels: email.
  • Impersonated: Unknown sender (not specified in article).

Red flags to watch for

  • Unexpected HTML email from an unfamiliar sender
  • Using an unpatched Zimbra webmail client vulnerable to CVE-2025-66376
  • Email viewing alone causing unusual account activity (preference changes, new app passcodes)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

Do I need to click a link for this Zimbra attack to work?

No. According to the joint alert, the attack triggers as soon as the victim views the malicious HTML email in Zimbra webmail, with no need to click a link or open a file.

What data does this attack steal?

Reported stolen data includes up to 90 days of emails, passwords, global address lists, two-factor authentication tokens, and application passcodes.

Who is being targeted?

The campaign has targeted organizations across defense, government, education, energy, law enforcement, media, NGOs, and technology sectors since July 2025.

What should organizations do about this Zimbra vulnerability?

Agencies recommend limiting use of the Zimbra webmail client until organizations apply the available patch, and monitoring for signs of account takeover such as changed preferences or newly created app passcodes.

Read the video transcript

Imagine this: you just open your inbox, glance at an email, and boom, your account’s already compromised. That’s the Zimbra webmail bug, CVE-2025-66376. Laundry Bear, also called Void Blizzard, sent malware-laden HTML emails that exploit a Zimbra XSS flaw. Just viewing the message in Zimbra can silently dump 90 days of your email, passwords, 2FA tokens, and app passcodes. Here’s the nasty part: there might be no link, no attachment, nothing obvious. The only clue is the context, an unexpected HTML email in Zimbra, and then weird account behavior: settings changed, new app passwords, logins you don’t recognize. If you use Zimbra and see a weird HTML email or odd changes in your mailbox, don’t ignore it, hit the phishing or report button and call IT. Let them know, "This might be that Zimbra CVE-2025-66376 thing."

Similar attacks

Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026
DocuSign Phish Uses “Blob” Pages in Your Browser

DocuSign Phish Uses “Blob” Pages in Your Browser

Researchers described a real phishing campaign where victims click through legitimate Microsoft services and end up on a fake login page that is generated inside their own browser. The phishing page uses a temporary “blob URL” (not a normal website) and can disappear after the session, making it…

September 10, 2026
Phish Page Built Inside Your Browser

Phish Page Built Inside Your Browser

Researchers reported a real phishing campaign that uses legitimate Microsoft OAuth and Teams pages to make the journey look trustworthy. Instead of hosting a fake login site on a suspicious domain, the attackers render the phishing page inside the victim’s own browser using a temporary “blob URL,”…

September 10, 2026
Blob URL Phish Hides Page Inside Your Browser

Blob URL Phish Hides Page Inside Your Browser

Barracuda observed a real phishing campaign that avoids hosting a traditional fake website. Instead, victims are led through Microsoft Teams to load a resource that their browser converts into a “blob URL,” rendering the phishing page only inside the victim’s browser, making it harder for scanners…

September 9, 2026
Recruiter, RMM, and Vishing Scams Hit Hard

Recruiter, RMM, and Vishing Scams Hit Hard

This weekly roundup includes multiple real-world social-engineering and phishing-style operations, including fake recruiter outreach pushing malicious Android apps, phishing emails that trick users into installing remote management tools, and vishing that reportedly led to compromised Okta…

September 4, 2026
Phishing PDF Drops Malware Via Fake Edge Loader

Phishing PDF Drops Malware Via Fake Edge Loader

Researchers describe BraZetsu, a Windows malware framework used by an initial-access broker to turn infected PCs into "access for sale" on a criminal marketplace. While the malware itself is technical, the article includes real-world delivery details pointing to phishing: victims are tricked into…

September 3, 2026