The record
Written from the 4 reports below. Nothing here is unsourced.
- A Russian state-supported espionage group exploited a previously unknown flaw in Zimbra's webmail client to read mailboxes at Western government and commercial organizations starting in July 2025.
- Simply viewing a malicious email was enough to trigger the exploit, which stole recent messages, contact directories, saved passwords and two-factor recovery codes.
- US agencies including the NSA and CISA issued a joint advisory on the campaign, which Zimbra patched on November 6, 2025.
- Targets included government, defense, transportation and financial organizations in NATO states, Ukraine and Africa, with US nuclear installations also on the target list.
- Patching alone is not enough, because stolen credentials and app-specific passwords survive the update and must be revoked separately.
What to watch next
- The NSA-CISA advisory assesses the group will very likely keep targeting Zimbra and other Western email systems.
- Proofpoint has seen no activity from the tracked actor TA488 since February 2026, so renewed activity would signal the campaign restarting.
- Zimbra 10.0 reached end of life on December 31, 2025, so organizations still on 10.0 face growing risk without a supported upgrade.
What changed4
Every report on this story, newest first. Times are when each outlet published.
The Hacker News[1]
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and WipersThe Hacker News[2]
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential RotationThe Hacker News[3]
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 AttacksThe Hacker News[4]
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
Who said what1
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Hacking Cat
pro-Ukrainian hacktivist entity
1 quote · 1 outlet
“a couple of the tools are ours, but the lockers are definitely not.”
In the article
…of developers who create, maintain, and modify the malware, which is subsequently used by various hacktivist groups." However, following the publication of the report, Hacking Cat posted on its Telegram channel that " a couple of the tools are ours, but the lockers are definitely not. " It has also alleged Kaspersky is attributing tools from completely unrelated actors to them and that it should "learn to reverse-engineer groups better." Toy Ghouls Deploys Custom Backdoor for the First Time Rounding…
Why it matters5
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- Ukrainian government and critical infrastructure email system compromise· immediate
- Western government commercial organizations using Zimbra credential theft· immediate
- Organizations using affected webmail systems (Zimbra, Kerio, SOGo, Roundcube) patch required· days
- End users of affected systems session hijacking· immediate
- Organizations using compressed archives supply chain risk· weeks
Coverage1
All filed from IndiaSingle origin
Named United States · Ukraine · 7-Zip · Albania · APT28 · CISA · CL-STA-1114 · Computer Emergency Response Team of Ukraine · Cyber Anarchy Squad · Dutch intelligence · ESET · Greece · Greg Lesnewich · Hacking Cat
- The Hacker NewsThree Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers[1]English national· neutral

- The Hacker NewsRussian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation[2]English national· neutral

- The Hacker NewsFake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks[3]English national· neutral

- The Hacker NewsRussian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes[4]English national· neutral

The 4 reports are listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.