Back to Blog
CVE-2025-66376: Zimbra Webmail — Zero-Click Data Exfiltration (June 2025)
vulnerabilities

CVE-2025-66376: Zimbra Webmail — Zero-Click Data Exfiltration (June 2025)

breachwire TeamJul 24, 20262 min read

CVE-2025-66376 — Zimbra Collaboration Suite Webmail

CVE-2025-66376 is a high-severity, zero-click vulnerability in the Zimbra Collaboration Suite webmail platform. It allows remote attackers to inject malicious JavaScript without user interaction, enabling credential theft, email archive exfiltration, and compromise of two-factor authentication scratch codes. This vulnerability is under active exploitation by Russian nation-state threat group CL-STA-1114 (Void Blizzard/LAUNDRY BEAR).

Attack Vector

Attackers leverage CVE-2025-66376 by sending specially crafted emails to Zimbra users. No user action is required; the exploit triggers automatically when the email is processed by the webmail interface. Malicious JavaScript is injected, granting attackers access to session tokens, credentials, email content, and search histories. Exfiltrated data is sent to attacker-controlled infrastructure, including IPs (e.g., 37.120.247.228, 185.86.79.95, 216.252.238.18) and domains such as analyticemailmeter.com, mailnalysis.com, and zimbra-metadata.com. The threat actor rotates command and control endpoints to evade detection and maintain persistence.

Who Is at Risk

All organizations running Zimbra Collaboration Suite webmail are exposed, especially those in government, defense, transportation, and finance. Confirmed victims include entities in NATO states, Ukraine, CIS countries, and Africa. The attack impacts both on-premises and cloud-hosted Zimbra deployments.

Patch & Mitigate

  • Patch: Apply the latest Zimbra security update addressing CVE-2025-66376 immediately. Monitor vendor advisories for hotfix release details.
  • Workaround: Disable webmail access if patching is delayed. Restrict external email delivery to critical mailboxes.
  • Detect: Review web server logs for anomalous requests to /service/soap, unexpected JavaScript execution, and outbound connections to known malicious IPs/domains (see IOCs above).

MITRE ATT&CK

  • TA0001 — Initial Access: Attackers gain access via zero-click email delivery exploiting Zimbra webmail.
  • TA0009 — Collection: Malicious scripts harvest credentials, emails, and authentication codes from compromised accounts.
  • TA0011 — Command and Control: Exfiltrated data is sent to rotating attacker infrastructure for persistent access.

Source: https://unit42.paloaltonetworks.com/russian-webmail-espionage/

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: