Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Zimbra Mailservers Targeted with Half-Click Exploits

1517b3caa495f6c4e832df9c75fc94667e3c233773f7fa4e056d5e30e5ead760

TLP:CLEAR
Active

SHA-256 Hash

Description

Russian-aligned threat actor TA488, also known as Void Blizzard and Laundry Bear, exploited a previously unknown vulnerability in Zimbra Collaboration Suite mailservers for at least five months during 2025. The vulnerability, later assigned CVE-2025-66376, was leveraged through half-click exploits embedded in HTML emails that executed upon opening without requiring user interaction. Upon successful exploitation, TA488 deployed ZimReaper malware to establish persistent access, steal credentials and two-factor authentication codes, and exfiltrate emails via DNS tunneling and HTTP requests. The campaigns primarily targeted Ukrainian government entities, alongside U.S. government, nuclear science facilities, and defense industrial base organizations. The actor used domains spoofing Zimbra telemetry services and regularly updated obfuscation techniques to evade detection. TA488 is believed to be a private contractor working for Russian intelligence services.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Zimbra Mailservers Targeted with Half-Click Exploits
Pattern Type
STIX
Confidence
75%
Valid From
Jul 24, 2026 02:00
Total Sightings
0
Added
Jul 24, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 1517b3caa495f6c4e832df9c75fc94667e3c233773f7fa4e056d5e30e5ead760

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.