Russian Hackers Exploit Zimbra Zero-Day to Steal Emails and 2FA Codes
A Russian state-backed espionage group exploited a critical Zimbra zero-day vulnerability (CVE-2025-66376) to compromise webmail accounts at government and commercial organizations. The flaw allowed attackers to execute malicious code simply by displaying a crafted email, enabling unauthorized access without additional user interaction.


Once inside, the attackers stole the last 90 days of emails, browser-saved passwords, two-factor authentication (2FA) recovery codes, and organizational address books. They also created app-specific passwords to maintain long-term access, allowing continued account compromise even after password resets.
Organizations using Zimbra should immediately upgrade to the latest supported version, reset affected user credentials, revoke app-specific passwords, regenerate 2FA recovery codes, and monitor email systems for suspicious activity. Regular patching and continuous email security monitoring remain essential to defend against advanced espionage campaigns.
NPAV Endpoint Security, help detect fileless malware, block malicious scripts, and protect users from credential-stealing attacks delivered through fake software downloads.