Back to Blog
CVE-2025-66376: Zimbra Collaboration — Zero-Click Credential Theft Campaign (June 2025)
vulnerabilities

CVE-2025-66376: Zimbra Collaboration — Zero-Click Credential Theft Campaign (June 2025)

breachwire TeamOct 4, 20262 min read

CVE-2025-66376 — Zimbra Collaboration

CVE-2025-66376 is a high-severity zero-day affecting Zimbra Collaboration Suite, allowing remote attackers to steal email credentials through malicious JavaScript executed when a user views a crafted email. The vulnerability is under active exploitation by the Russian APT group Laundry Bear, with no user interaction required beyond viewing the email.

Attack Vector

Attackers deliver a specially crafted email containing obfuscated JavaScript. When the email is viewed in an unpatched Zimbra webmail client, the script executes in the user's context, harvesting credentials and session tokens. Exfiltration occurs via HTTPS and DNS to attacker-controlled domains, including mailnalysis.com, emailanalytics.com.ua, zimbrastat.com, zimbra-metadata.com, istc-cloud.com, and zmailanalytics.com. The exploit bypasses MFA and establishes persistent access for ongoing mailbox monitoring and data theft.

Who Is at Risk

All organizations running unpatched Zimbra Collaboration Suite servers are at immediate risk, particularly those in North America. The attack impacts both on-premises and cloud-hosted Zimbra deployments. Any organization that has not applied the latest security updates is vulnerable to credential theft, mailbox compromise, and further lateral movement.

Patch & Mitigate

  • Patch: Apply the latest Zimbra security update addressing CVE-2025-66376 immediately. Check Zimbra advisories for the exact patch version and release notes.
  • Workaround: Disable webmail access if patching is not immediately possible. Restrict external email delivery and monitor for suspicious messages.
  • Detect: Review mail logs for access to or exfiltration attempts involving the listed IOCs. Monitor for outbound connections to mailnalysis.com, emailanalytics.com.ua, zimbrastat.com, zimbra-metadata.com, istc-cloud.com, and zmailanalytics.com. Audit authentication logs for anomalous mailbox access and failed MFA events.

MITRE ATT&CK

  • T1203 — Exploitation for Client Execution: The attacker exploits a vulnerability in the Zimbra webmail client to execute malicious code.
  • T1027.017 — Obfuscated Files or Information: JavaScript payloads are heavily obfuscated to evade detection.
  • T1566 — Phishing: Malicious emails are delivered to targets to trigger the exploit upon viewing.

Source: https://securityaffairs.com/195901/apt/us-agencies-warn-of-laundry-bear-campaign-targeting-unpatched-zimbra-servers.html

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: