Zimbra Zero-Day Email: Preview Triggers Espionage

Hack Read · High sophistication
Last updated July 30, 2026

A Russia-aligned espionage group sent specially crafted HTML emails that could compromise vulnerable Zimbra webmail servers just by being opened or previewed, no link clicks or attachments needed. The exploit ran JavaScript inside the email body to steal mailbox data and credentials, then set up persistent access by creating an application password.

How the attack worked

This campaign relied on a previously unknown Zimbra webmail flaw that could be triggered simply by opening or previewing an HTML email. The message body contained embedded JavaScript that executed automatically once the email was displayed in a vulnerable Zimbra client, no attachment opening or link clicking required. Once triggered, the exploit harvested the victim's email address, browser-saved password, 2FA scratch codes, Zimbra environment details, address directory entries, and up to 90 days of email history.

After gaining access, the attacker created an application password named ZimbraWeb. This gave persistent mailbox access through IMAP, POP3, or SMTP and effectively bypassed normal two-factor authentication protections, allowing continued access even if the victim changed their primary password.

Why it succeeded

The attack succeeded largely because it removed the human decision point that most awareness training focuses on. Employees are commonly taught to scrutinize links and attachments, but this exploit required no interaction beyond viewing the message in a webmail preview pane. The emails also used generic business outreach themes and were sent from attacker-controlled Proton Mail addresses or from accounts compromised in earlier operations, which helped the messages appear more credible to recipients and reduced suspicion.

What to watch for

  • Unexpected business outreach emails from unfamiliar senders, especially those using generic or vague business themes
  • Messages originating from webmail providers like Proton Mail or from accounts that seem inconsistent with prior communication patterns
  • HTML-heavy or unusually formatted email content, since the exploit was delivered through the HTML body
  • Unexpected application passwords, particularly ones named ZimbraWeb, appearing in mailbox or admin audit logs

How to build resistance

Because this technique bypassed the usual click-based defenses, organizations using Zimbra webmail should prioritize patching exposed servers promptly. IT and helpdesk teams should routinely review server logs for requests that create new application passwords, particularly any named ZimbraWeb, and revoke unauthorized ones immediately. Awareness training should also evolve beyond “don't click the link” messaging to include the reality that simply previewing an email on a vulnerable system can be enough to trigger compromise. Encouraging staff, especially those in government, defense, energy, and research roles, to report unexpected business emails even when no action is requested can help surface early indicators of this kind of preview-triggered attack.

Key findings

  • Victims could be compromised by opening or previewing a malicious email in a vulnerable Zimbra webmail client, no clicks required.
  • The attacker used a previously unknown Zimbra flaw (CVE-2025-66376) by embedding malicious JavaScript in an HTML email body.
  • Stolen data included email address, browser-saved password, 2FA scratch codes, Zimbra environment info, address directory entries, and up to 90 days of email.
  • The threat actor created an application password named “ZimbraWeb” for persistent mailbox access via IMAP/POP3/SMTP, bypassing normal 2FA.
  • Emails were sent from attacker-controlled Proton Mail addresses or from accounts previously compromised to improve credibility and reach new targets.

Who’s being targeted

  • Commonly targeted roles: All employees using webmail, Executives, Government and defense staff, IT administrators (email/server admins), Helpdesk/service desk.
  • Affected industries: Government, Defense, Energy (including nuclear), Scientific research, European public sector and commercial organizations.
  • Attack channels: email.
  • Impersonated: Cooperation Belgian Foundation (as referenced in lure image caption).

Red flags to watch for

  • Unexpected “generic business” outreach from an unknown sender
  • Sender originates from webmail providers or unusual accounts (e.g., Proton Mail)
  • Email content is HTML-heavy/unusual formatting (implied by HTML/JS exploit delivery)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the Zimbra zero-day attack work without clicking anything?

When a recipient opened or previewed the malicious email in a vulnerable Zimbra webmail client, malicious JavaScript embedded in the HTML body executed automatically, requiring no clicks or attachments.

What data did the attackers steal?

Stolen data included the victim's email address, browser-saved password, 2FA scratch codes, Zimbra environment information, address directory entries, and up to 90 days of email.

How did attackers maintain access after the initial compromise?

The threat actor created an application password named ZimbraWeb, which allowed continuing mailbox access through IMAP, POP3, or SMTP while bypassing normal 2FA.

Who was targeted in this campaign?

Targets included government and defense staff, executives, administrative staff, IT administrators, and helpdesk personnel, primarily in government, defense, energy, and scientific research sectors.

Read the video transcript

Imagine this: you just preview an email in Zimbra… and boom, your whole mailbox is hacked. A Russia‑aligned group used a Zimbra zero‑day, CVE‑2025‑66376. Just opening their HTML email ran hidden JavaScript that quietly stole up to 90 days of mail, saved passwords, even 2FA scratch codes. Their lure? Boring, generic business outreach: "Cooperation Belgian Foundation" from random Proton Mail or odd accounts. No scary links, just enough to make you preview it in webmail. If you use Zimbra and see odd "Cooperation"‑style emails, or IT spots an app password named "ZimbraWeb" on your account, report it to IT immediately and stop using webmail until they clear you.

Similar attacks

Govt-Themed Phishing Spreads Cruciferra Malware

Govt-Themed Phishing Spreads Cruciferra Malware

Proofpoint observed real phishing campaigns using government-themed lures to trick people into downloading ZIP files that install malware. The campaigns used a “crypter” service called Cruciferra to help common remote-access and data-stealing malware evade detection. Financial services, healthcare,…

July 21, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Hotel Wi‑Fi Lures Steal M365 Logins, Drop Malware

Hotel Wi‑Fi Lures Steal M365 Logins, Drop Malware

Microsoft says Russian-linked threat actors compromised hotel and conference guest Wi‑Fi “captive portal” networks to redirect travelers to fake Microsoft 365 sign-in pages, device-code phishing, or fake update pages. The goal was to steal cloud credentials (including Entra ID device codes) and…

August 4, 2026
“No-Action” Emails Trigger OWA Mailbox Takeover

“No-Action” Emails Trigger OWA Mailbox Takeover

Russian-linked threat actors sent generic-looking informational emails that required no clicking, but simply opening them in vulnerable Outlook Web Access (OWA) could trigger a hidden exploit. The campaign targeted government and multiple industries, then installed a stealthy browser-based implant…

July 30, 2026
Laundry Bear Uses “Half-Click” OWA Email Exploit

Laundry Bear Uses “Half-Click” OWA Email Exploit

UK and US cyber authorities and Proofpoint reported a real campaign where the Russian-linked group “Laundry Bear” (TA488) sent emails that could infect victims simply by being opened in Outlook Web Access. The email’s HTML triggers the server to run attacker code, installing a mailbox-stealing…

July 29, 2026
Phishing Lab Used WebDAV to Push Fake “PDF” Malware

Phishing Lab Used WebDAV to Push Fake “PDF” Malware

Investigators found an exposed WebDAV server being used as a “malware delivery lab” with over 1,000 files for testing lures, filenames, and execution tricks. One active campaign impersonated Mexico’s CURP ID lookup site and delivered malware by opening a remote WebDAV folder via a Windows…

July 20, 2026