Intelligence
criticalCampaignActive

Russian state group weaponised Zimbra zero-day for systematic email and 2FA exfiltration

A Russian espionage group exploited an unknown flaw in Zimbra webmail to harvest email, directory data, and 2FA recovery codes from Western organisations over an extended period. The attack required only message open to trigger payload execution.

S
Sebastion

Affected

Zimbra webmail

A Russian state-supported espionage group has conducted sustained reconnaissance against Western targets by exploiting a previously unknown vulnerability in Zimbra's webmail client. The group maintained mailbox access over months, systematically extracting the last 90 days of messages, complete organisational directory listings, stored browser credentials, and two-factor authentication recovery codes. The attack chain required no user interaction beyond opening a malicious email message, suggesting a reliable memory corruption or similar remote code execution primitive.

This campaign represents a sophisticated targeting of the webmail trust boundary. Most organisations assume that inbox access is sufficiently protected by edge controls and gateway scanning, yet this operation demonstrates how a zero-day in the client-side renderer can bypass these assumptions entirely. The recovery of 2FA codes alongside email access is particularly significant: it indicates the attackers' intent to establish persistent lateral access or credentials for future operations. The 90-day mailbox window suggests either a scanning campaign to identify targets of interest or a methodical data collection operation.

The likely impact spans diplomatic, defence, and technology sector organisations across the West. Zimbra maintains meaningful market share in corporate and government email deployments, particularly in organisations seeking alternatives to Microsoft Exchange. Organisations running vulnerable versions have likely had mailbox contents, directory information, and authentication materials compromised without triggering conventional security logs.

Defenders should immediately assess Zimbra deployment scope and patch status. Organisations should assume that if they ran unpatched Zimbra instances during the exploitation window, sensitive email, organisational structure, and cached credentials may have been exfiltrated. Priority actions include credential rotation for users of affected systems, review of 2FA recovery code distribution logs, and forensic review of mailbox access patterns. External DNS and email delivery logs may provide initial indicators of data exfiltration.

This incident underscores a persistent vulnerability in email security posture: webmail clients remain rich attack surface despite decades of security focus on email gateways. State actors continue to prioritise mailbox access as a high-value intelligence collection vector, and zero-days in widely deployed mail clients remain among the most effective tools for achieving it. The incident should prompt organisations to reconsider whether client-side email rendering and storage of sensitive credentials in browsers represents an acceptable risk.