
Govt-Themed Phishing Spreads Cruciferra Malware
Proofpoint observed real phishing campaigns using government-themed lures to trick people into downloading ZIP files that install malware. The campaigns used a…
A Russia-aligned espionage group sent specially crafted HTML emails that could compromise vulnerable Zimbra webmail servers just by being opened or previewed, no link clicks or attachments needed. The exploit ran JavaScript inside the email body to steal mailbox data and credentials, then set up persistent access by creating an application password.
This campaign relied on a previously unknown Zimbra webmail flaw that could be triggered simply by opening or previewing an HTML email. The message body contained embedded JavaScript that executed automatically once the email was displayed in a vulnerable Zimbra client, no attachment opening or link clicking required. Once triggered, the exploit harvested the victim's email address, browser-saved password, 2FA scratch codes, Zimbra environment details, address directory entries, and up to 90 days of email history.
After gaining access, the attacker created an application password named ZimbraWeb. This gave persistent mailbox access through IMAP, POP3, or SMTP and effectively bypassed normal two-factor authentication protections, allowing continued access even if the victim changed their primary password.
The attack succeeded largely because it removed the human decision point that most awareness training focuses on. Employees are commonly taught to scrutinize links and attachments, but this exploit required no interaction beyond viewing the message in a webmail preview pane. The emails also used generic business outreach themes and were sent from attacker-controlled Proton Mail addresses or from accounts compromised in earlier operations, which helped the messages appear more credible to recipients and reduced suspicion.
Because this technique bypassed the usual click-based defenses, organizations using Zimbra webmail should prioritize patching exposed servers promptly. IT and helpdesk teams should routinely review server logs for requests that create new application passwords, particularly any named ZimbraWeb, and revoke unauthorized ones immediately. Awareness training should also evolve beyond “don't click the link” messaging to include the reality that simply previewing an email on a vulnerable system can be enough to trigger compromise. Encouraging staff, especially those in government, defense, energy, and research roles, to report unexpected business emails even when no action is requested can help surface early indicators of this kind of preview-triggered attack.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
When a recipient opened or previewed the malicious email in a vulnerable Zimbra webmail client, malicious JavaScript embedded in the HTML body executed automatically, requiring no clicks or attachments.
Stolen data included the victim's email address, browser-saved password, 2FA scratch codes, Zimbra environment information, address directory entries, and up to 90 days of email.
The threat actor created an application password named ZimbraWeb, which allowed continuing mailbox access through IMAP, POP3, or SMTP while bypassing normal 2FA.
Targets included government and defense staff, executives, administrative staff, IT administrators, and helpdesk personnel, primarily in government, defense, energy, and scientific research sectors.
Imagine this: you just preview an email in Zimbra… and boom, your whole mailbox is hacked. A Russia‑aligned group used a Zimbra zero‑day, CVE‑2025‑66376. Just opening their HTML email ran hidden JavaScript that quietly stole up to 90 days of mail, saved passwords, even 2FA scratch codes. Their lure? Boring, generic business outreach: "Cooperation Belgian Foundation" from random Proton Mail or odd accounts. No scary links, just enough to make you preview it in webmail. If you use Zimbra and see odd "Cooperation"‑style emails, or IT spots an app password named "ZimbraWeb" on your account, report it to IT immediately and stop using webmail until they clear you.

Proofpoint observed real phishing campaigns using government-themed lures to trick people into downloading ZIP files that install malware. The campaigns used a…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Russian-linked threat actors sent generic-looking informational emails that required no clicking, but simply opening them in vulnerable Outlook Web Access…

UK and US cyber authorities and Proofpoint reported a real campaign where the Russian-linked group “Laundry Bear” (TA488) sent emails that could infect victims…

Investigators found an exposed WebDAV server being used as a “malware delivery lab” with over 1,000 files for testing lures, filenames, and execution tricks.…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…