
Russian Hackers Exploit Zimbra Zero-Day to Steal Emails Without User Interaction
CybersecurityCyberAttacksMalwareCyberCrimeRussiaTA488VoidBlizzardLaundryBearVulnerabilityZimbraZeroDayEmailExfiltrationEspionage
Russian hackers from the TA488 group (also linked to Void Blizzard and Laundry Bear) exploited an unpatched Zimbra webmail zero-day vulnerability to steal credentials and up to 90 days of email messages from targeted victims. The flaw was triggered simply by opening or previewing emails, requiring no user interaction such as link clicks. The attack targeted Zimbra Collaboration Suite, a widely used email and collaboration platform, though specific victim organizations or sectors were not disclosed. No CVE ID was mentioned for the vulnerability, nor were exact dates of exploitation provided. The campaign highlights the group’s focus on email exfiltration for intelligence gathering or further compromise.