This Russian cybercrime campaign can infect a user just by viewing an email


  • Proofpoint reports Russian TA488 exploited Zimbra zero‑day CVE‑2025‑66376 in espionage campaigns
  • “Half‑click exploit” let attackers compromise systems when victims merely viewed malicious emails
  • Targets included NATO, Ukrainian government, and defense entities; group vanished after Feb 2026 exposure

Russian state-sponsored cybercriminals have been abusing a zero-day vulnerability in the Zimbra email and collaboration platform to conduct espionage against western targets – primarily military and government agencies, experts have warned.

Cybersecurity researchers Proofpoint claim the campaign has been ongoing for at least a year, possibly longer, describing it as a “half-click exploit”, because the victims don’t even need to do anything specific in order to get infected.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *