Zimbra Half-Click Webmail Zero-Day Exploited by Russian Spies to Steal Emails, Credentials
- Russia alignment: Cybersecurity advisories and threat reporting warn of Russia-aligned espionage campaigns, some potentially operating under the GRU.
- Half-click: The Void Blizzard group uses half-click XSS zero-days against Zimbra, with other russian spies also exploiting mDaemon, SOGo, and Roundcube.
- SpyPress malware: One other group’s SpyPress payload steals credentials, contacts, and emails from targeted webmail servers.
A webmail-targeting campaign run by the threat actor tracked as Void Blizzard, LAUNDRY BEAR, CL-STA-1114, and TA488 (formerly UNK_PitStop), was exploiting half-click cross-site scripting (XSS) zero-days against Zimbra (CVE-2025-27915) for at least five months during 2025.
Additional reporting on Russia-aligned threat actor TA458’s Operation RoundPress adds exploits targeting mDaemon (CVE-2025-3929), SOGo (CVE-2026-8496), and Roundcube to read and steal data from Western entities.
A joint intelligence agencies advisory, Proofpoint Threat Research, and Palo Alto Networks' Unit 42 detailed the continued advance of the campaign. The tactics of gathering credentials for the mailboxes of these targets and exfiltrating them are common across TA488 and the previously attributed TA458 and TA422.
No Click Required: How the Half-Click Exploits Work
The so-called "half-click" XSS exploits require no social engineering, no link click, and no attachment to open. Just opening the malicious email in a webmail viewer is enough to get compromised.
The trick lies in abusing features that aren't properly sanitized, things like event handlers that quietly execute arbitrary JavaScript the moment the message renders. Proofpoint has watched TA458 burn through exploits in:
- Zimbra (CVE-2025-27915),
- mDaemon (CVE-2025-3929),
- SOGo (CVE-2026-8496),
- two separate Roundcube flaws (CVE-2023-43770, CVE-2024-42009)
SpyPress and Targets
Beginning around July 2025, Void Blizzard shifted toward a more technical method of email compromise, using custom malware to target and exfiltrate sensitive user information from organizations using Zimbra Collaboration Suite (ZCS). According to the advisory, these include:
- Last 90 days of emails,
- Email address,
- Password,
- Global Address List (GAL),
- Two-factor authentication (2FA) tokens,
- Newly-created Application Passcode.
Proofpoint reported TA458 leveraged the SpyPress malware, obfuscated JavaScript with a version tailored to each mailserver that attempts six distinct persistence mechanisms, including reverse shells and dropped PHP webshells.
TA458's targeting leans heavily toward Ukraine. Researchers believe the group is likely aligned with Russia’s General Staff Main Intelligence Directorate (GRU), possibly tied to the 85th Main Special Service Center (Unit 26165) or Unit 20728.
Government entities there remain the primary focus, alongside military and government installations across Albania, Greece, Moldova, and Türkiye, and financial organizations across NATO member states, Ukraine, Commonwealth of Independent States (CIS) countries, and Africa.
Last week, Dutch intelligence warned that Russian hackers are turning doorbell and security cameras into spy tools to track NATO military logistics. In May 2025, researchers reported that Void Blizzard was impersonating the European Defense & Security Summit in phishing emails.









