Ta488 Targets Zimbra Mailservers with Half Click Exploits
Overview
🚨 Proofpoint has uncovered that the Russia-aligned threat actor TA488 (also known as Void Blizzard or Laundry Bear) has been exploiting a previously unknown vulnerability in Zimbra mailservers for at least five months during 2025. This issue was patched with CVE-2025-66376. After successful exploitation, TA488 established persistent access to the systems and exfiltrated emails from targeted users.
Targeted Entities
The campaigns primarily targeted Ukrainian government entities, as well as various government, high science, and defense industrial base targets in the United States. TA488 is one of several Russian-aligned groups that Proofpoint tracks, utilizing half-click exploits to target email servers. This stealthy method only requires a user to open the email for the exploit code to execute.
Exploit Details
Since at least July 2025, TA488 has leveraged an exploit in Zimbra Collaboration Suite mailservers to target Ukrainian entities and critical infrastructure in the United States. The messages sent by TA488 exploit CVE-2025-66376 from both adversary-controlled Proton Mail accounts and previously compromised addresses. Notably, these messages use generic lures and do not require the targeted user to click on a link or open an attachment.
The XSS exploit is embedded directly in the HTML body of the message and activates as soon as the victim opens or previews it in the vulnerable Zimbra webmail client. The vulnerability lies in Zimbra’s client-side HTML sanitizer, allowing TA488 to hide malicious tags within the message.
Evasion Techniques
Since at least October 2025, TA488 has begun wrapping its final payload in a basic XOR loop, enhancing its ability to evade secure email gateway detection mechanisms. The script running in the browser context grants access to all data available within the authenticated webmail session, allowing the attacker to steal sensitive information.
Conclusion
The malware, tracked as ZimReaper, attempts to dump all contacts in the server’s directory and exfiltrate emails from the last 90 days. Proofpoint’s collaboration with U.S. government partners has confirmed the association of TA488 with Russian intelligence.
For more detailed information, please visit the full article: Read full article