This Russian cybercrime campaign can infect a user just by viewing an email


  • Proofpoint reports that Russian TA488 exploited Zimbra zero-day CVE-2025-66376 in espionage campaigns
  • “Half-click exploit” lets attackers compromise systems when victims simply view malicious emails
  • Targets included NATO, the Ukrainian government and defense units; the group disappeared after exposure in February 2026

Russian state-sponsored cybercriminals have abused a zero-day vulnerability in the Zimbra email and collaboration platform to conduct espionage against Western targets – primarily military and government agencies, experts have warned.

Cybersecurity researchers Proofpoint claim the campaign has been running for at least a year, possibly longer, describing it as a “half-click exploit” because victims don’t even need to do anything specific to become infected.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top