- Proofpoint reports that Russian TA488 exploited Zimbra zero-day CVE-2025-66376 in espionage campaigns
- “Half-click exploit” lets attackers compromise systems when victims simply view malicious emails
- Targets included NATO, the Ukrainian government and defense units; the group disappeared after exposure in February 2026
Russian state-sponsored cybercriminals have abused a zero-day vulnerability in the Zimbra email and collaboration platform to conduct espionage against Western targets – primarily military and government agencies, experts have warned.
Cybersecurity researchers Proofpoint claim the campaign has been running for at least a year, possibly longer, describing it as a “half-click exploit” because victims don’t even need to do anything specific to become infected.
Usually, when an attack is carried out via email, the victim must at least download a file or click on a link. In this case, a cross-site scripting (XSS) vulnerability in the Zimbra web-based email service allowed the Russians to infiltrate the computers as soon as the victim sees the email, nothing more.
Latest videos fromTechRadar
Targeted NATO and Ukraine
The vulnerability in question is now tracked as CVE-2025-66376. It was assigned a severity score of 7.2/10 (high), and was patched in November 2025. However, the threat actors have been exploiting it long before Zimbra patched it.
Proofpoint says several groups over the years have been observed abusing this flaw. This time, however, the group in question is tracked as TA488, also known as Laundry Bear or Void Blizzard.
“After successful exploitation, TA488 established persistent access to the systems and exfiltrated emails from the targeted users,” Proofpoint’s report reads. In addition to emails, the crooks hunted for passwords, email folders, two-factor authentication tokens, and more. The group has “consistently” targeted NATO and Ukrainian government organizations along with units in the defense industrial base,
The group appears to be defunct now, as researchers could find no activity beyond February 2026. At that time, security researchers Seqrite revealed a detailed breakdown of the group’s infrastructure and modus operandi, which resulted in TA488 burning months-old setups and disappearing.
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews and opinions in your feeds.



