This Russian cybercrime campaign can infect a user just by viewing an email
Date:
Sun, 26 Jul 2026 11:30:00 +0000
Description:
A high-severity flaw in Zimbra allowed Russian criminals easy access, where they stole important secrets.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Proofpoint reports Russian
TA488 exploited Zimbra zeroday CVE202566376 in espionage campaigns Halfclick exploit let attackers compromise systems when victims merely viewed malicious emails Targets included NATO, Ukrainian government, and defense entities; group vanished after Feb 2026 exposure Russian state-sponsored cybercriminals have been abusing a zero-day vulnerability in the Zimbra email and collaboration platform to conduct espionage against western targets - primarily military and government agencies, experts have warned.
Cybersecurity researchers Proofpoint claim the campaign has been ongoing for at least a year, possibly longer, describing it as a half-click exploit, because the victims dont even need to do anything specific in order to get infected. Usually, when an attack is done via email, the victim is required
to at least download a file or click a link. In this case, a cross-site scripting (XSS) vulnerability in the Zimbra web-based email service allowed the Russians to infiltrate the computers as soon as the victim views the email, nothing more. Latest Videos From TechRadar Watch full video here: Targeting NATO and Ukraine The vulnerability in question is now tracked as CVE-2025-66376. It was assigned a severity score of 7.2/10 (high), and was patched in November 2025. However, the threat actors have been leveraging it long before Zimbra patched it up.
Proofpoint says numerous groups were observed, throughout the years, abusing this flaw. This time around, though, the group in question is tracked as TA488, also known as Laundry Bear or Void Blizzard. You may like Hackers are establishing persistence in hospitality and hotels by posing as guests with poisoned ZIP archives, but no one knows what their plan is Free email
accounts contributing to nearly half of all commercial spam US and security allies warn Russian attacks on critical infrastructure are ramping up
After successful exploitation, TA488 established persistent access to the systems and exfiltrated emails from the targeted users, Proofpoints report reads. Besides emails, the crooks hunted for passwords, email directories, two-factor authentication tokens, and more. The group has been consistently targeting NATO and Ukrainian government organizations, alongside entities in the defense industrial base,
The group seems to be defunct now, since the researchers could not find any activity post February 2026. At that time, security researchers Seqrite disclosed a detailed breakdown of the groups infrastructure and modus operandi, resulting in TA488 burning down months-old setups and vanishing.
Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/this-russian-cybercrime-campaign-can-in fect-a-user-just-by-viewing-an-email
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)