Russian State-Sponsored Actors Exploit Zimbra Zero-Click Vulnerability
Runtime Rebel has confirmed ongoing cyberespionage activity, tracked by Unit 42 as CL-STA-1114, which targets Zimbra webmail platforms globally. This campaign, attributed to a Russian threat actor also known as Void Blizzard and LAUNDRY BEAR (consistent with activity from APT28), leverages a critical zero-click vulnerability, CVE-2025-66376, in the Zimbra Collaboration Suite (ZCS). The exploitation allows for the unauthorized exfiltration of sensitive user data, including login credentials, email archives, and search histories, without any interaction from the recipient.
This sophisticated operation underscores the persistent threat posed by state-sponsored groups targeting widely used communication platforms. Organizations using Zimbra Collaboration Suite are at significant risk if their systems remain unpatched, facing potential breaches of confidential information and compromise of user accounts, as detailed by Unit 42.
Technical Analysis of CVE-2025-66376 Exploitation
The CL-STA-1114 campaign, active since at least 2024, began exploiting Zimbra servers in July 2025. The attack sequence initiates with a zero-click phishing email. These emails contain either an HTML attachment or embedded HTML within the message body, designed to pique recipient interest through news headlines. The embedded HTML includes an obfuscated division with a Base64-encoded script. This obfuscated section creates an invisible Scalable Vector Graphics (SVG) element. Upon loading, this SVG element decodes the Base64 script into a JavaScript payload, which is then injected directly into the victim’s browser.
Once executed, the malicious JavaScript payload systematically exfiltrates various sensitive data types from the victim’s Zimbra webmail to a hard-coded command and control (C2) server. Data collected includes:
- Login credentials
- Email archives
- User search histories
Over the campaign’s duration, Unit 42 observed minimal changes to the JavaScript payload, indicating a stable and effective exploit. The threat actors have utilized at least nine distinct IP addresses and nine domains for their C2 infrastructure, with each server remaining active for an average of 35.4 days before being rotated. This transient C2 setup makes tracing and blocking infrastructure challenging for defenders, highlighting the need for advanced threat detection capabilities.
Prioritizing Zimbra Collaboration Suite CVE-2025-66376 Patch Guidance
The immediate priority for all organizations utilizing Zimbra Collaboration Suite is to apply available patches to address CVE-2025-66376. Given the zero-click nature of this vulnerability and its active exploitation by a state-sponsored actor, patching must be treated as critical. Failure to do so leaves organizations exposed to ongoing espionage attempts and significant data loss.
How to Detect CVE-2025-66376 Exploit Attempts and Mitigate Risks
Beyond patching, security teams should implement several measures to enhance defenses against this and similar threats:
- Patch Management: Regularly update all instances of Zimbra Collaboration Suite to the latest patched versions. Establish a rigorous patch management process to ensure timely deployment of security updates.
- Email Security: Deploy advanced email security solutions capable of detecting and blocking sophisticated phishing attempts, including those with embedded HTML and obfuscated scripts. Focus on solutions that can analyze email content for suspicious JavaScript and SVG elements.
- Network Monitoring: Monitor network traffic for connections to unusual or suspicious IP addresses and domains, particularly those that may serve as C2 infrastructure. Organizations should investigate any outbound connections from Zimbra servers to unknown external destinations.
- Endpoint Detection and Response (EDR): Utilize EDR solutions to detect malicious script execution in browsers or unusual process behavior on client machines that interact with Zimbra webmail.
- User Awareness Training: While this is a zero-click exploit, general awareness training regarding phishing emails remains important, as threat actors constantly evolve their initial access vectors.
- Incident Response Plan: Ensure an up-to-date incident response plan is in place to quickly detect, contain, and eradicate any compromise related to this campaign.
Related: Zimbra Zero-Click Exploitation by Russian APT for Email Theft, Zimbra Zero-Day Exploited by Laundry Bear Against US & Ukraine