A Russian cyberespionage group is breaking into Zimbra webmail servers to steal user login details
and email archives. The attackers send a booby-trapped news email that runs on its own, with no click
or action needed from the reader, by abusing an unpatched flaw in Zimbra Collaboration Suite (CVE
2025-66376). Any organisation still running an unpatched Zimbra server should apply the fix now, as
attackers are actively hunting for exposed instances
1. Campaign Timeline
Unit 42 tracks this activity as CL-STA-1114 and assesses it as overlapping with the Russian actor other vendors call Void Blizzard and LAUNDRY BEAR. The operators have been active since at least 2024, and the run against Zimbra servers started in July 2025. Across the campaign, Unit 42 recorded at least nine C2 IP addresses and nine C2 domains, each server live for an average of 35.4 days. The JavaScript payload changed little over that period. Attackers keep targeting unpatched Zimbra Collaboration Suite instances using CVE-2025-66376.
2. Targeting Profile
The group targets Zimbra webmail run by government, defence, transportation, and financial organisations. Victims sit across NATO member states, Ukraine, Commonwealth of Independent States (CIS) countries, and Africa. The goal is espionage: stealing mailbox contents and the credentials needed to keep reading them.
3. Attack Chain
- Phishing lure: The victim receives an email with an HTML attachment or HTML embedded in the message body, dressed up as a news headline to draw attention.
- Zero-click trigger: The HTML hides an obfuscated division holding a Base64-encoded script. On load it builds an invisible SVG element that decodes the script into a JavaScript payload, exploiting CVE-2025-66376 in Zimbra Collaboration Suite with no click required.
- Payload execution: The decoded JavaScript runs in the victim’s browser session against the Zimbra webmail interface.
- Exfiltration:The script sends the victim’s webmail data to a hard-coded command and control server, including credentials, session tokens, and 90 days of stored mail.
4. Payload Capabilities
- Account credentials: Email address and password, giving the attacker direct sign-in access to the mailbox.
- Session and CSRF tokens: Cross-Site Request Forgery tokens that let the attacker act inside the authenticated webmail session.
- 2FA scratch codes: Two-factor authentication scratch codes, which can bypass the account’s second login factor.
- Mail and search history: The victim’s last 90 days of email and search history, plus email archives.
- Host details: System and environment details and the Zimbra web configuration, used to profile the target.
5. Adversary Toolkit
| Tool / Indicator | Type | Function |
| HTML/SVG dropper | HTML, Base64-encoded JavaScript | News-themed lure that hides a Base64 script and builds an invisible SVG to decode and inject the payload. |
| Zimbra exfiltration payload | JavaScript | Runs in the webmail session, harvests credentials, tokens, and mail, and sends them to the C2. |
6. Indicators of Compromise (IOCs)
Type Indicator
IP – 37.120.247[.]228
IP – 64.226.124[.]190
IP – 104.248.134[.]194
IP – 185.86.79[.]95
IP – 193.238.152[.]66
IP – 194.156.103[.]193
IP – 216.252.238[.]18
IP – 216.252.238[.]64
IP – 216.252.238[.]104
Domain – analyticemailmeter[.]com
Domain – emailanalytics[.]com[.]ua
Domain – istc-cloud[.]com
Domain – mailnalysis[.]com
Domain – synacorzimbra[.]nl
Domain – zimbra-metadata[.]com
Domain – zimbrastat[.]com
Domain – zimbrasoft[.]com[.]ua
Domain – zmailanalytics[.]com
7. Recommendations
- Find every Zimbra Collaboration Suite webmail server in your estate and confirm it is patched against CVE 2025-66376. Unpatched, internet-facing instances are the entry point for this campaign.
- Apply the Zimbra security update for CVE-2025-66376 on all affected servers. There is no reliable workaround while the flaw stays open.
- For any mailbox on an unpatched server, treat the account as exposed: reset passwords, revoke and reissue 2FA scratch codes, and clear active webmail sessions.
- Filter inbound mail for HTML attachments and embedded HTML carrying obfuscated Base64 script or hidden SVG elements, and sandbox suspicious attachments before delivery.
- Block the IOCs at their respective controls.
8. Sources
- https://unit42.paloaltonetworks.com/russian-webmail-espionage
- https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-b
lizzard-targets-critical-sectors-for-espionage/ - https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/
Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn
No related posts found.