Zimbra Half-Click Webmail Zero-Day Exploited by Russian Spies to Steal Emails, Credentials

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer
Key Takeaways
  • Russia alignment: Cybersecurity advisories and threat reporting warn of Russia-aligned espionage campaigns, some potentially operating under the GRU.
  • Half-click: The Void Blizzard group uses half-click XSS zero-days against Zimbra, with other russian spies also exploiting mDaemon, SOGo, and Roundcube.
  • SpyPress malware: One other group’s SpyPress payload steals credentials, contacts, and emails from targeted webmail servers.

A webmail-targeting campaign run by the threat actor tracked as Void Blizzard, LAUNDRY BEAR, CL-STA-1114, and TA488 (formerly UNK_PitStop), was exploiting half-click cross-site scripting (XSS) zero-days against Zimbra (CVE-2025-27915) for at least five months during 2025. 

Additional reporting on Russia-aligned threat actor TA458’s Operation RoundPress adds exploits targeting mDaemon (CVE-2025-3929), SOGo (CVE-2026-8496), and Roundcube to read and steal data from Western entities.

A joint intelligence agencies advisory, Proofpoint Threat Research, and Palo Alto Networks' Unit 42 detailed the continued advance of the campaign. The tactics of gathering credentials for the mailboxes of these targets and exfiltrating them are common across TA488 and the previously attributed TA458 and TA422

No Click Required: How the Half-Click Exploits Work

The so-called "half-click" XSS exploits require no social engineering, no link click, and no attachment to open. Just opening the malicious email in a webmail viewer is enough to get compromised. 

TA458 lure email using compromised sender to target Ukrainian entities in March 2026 | Source: Proofpoint
TA458 lure email using compromised sender to target Ukrainian entities in March 2026 | Source: Proofpoint
TA488 “Cooperation Belgian Foundation” lure email from October 2025 | Source: Palo Alto
TA488 “Cooperation Belgian Foundation” lure email from October 2025 | Source: Palo Alto

The trick lies in abusing features that aren't properly sanitized, things like event handlers that quietly execute arbitrary JavaScript the moment the message renders. Proofpoint has watched TA458 burn through exploits in:

SpyPress and Targets

Beginning around July 2025, Void Blizzard shifted toward a more technical method of email compromise, using custom malware to target and exfiltrate sensitive user information from organizations using Zimbra Collaboration Suite (ZCS). According to the advisory, these include:

The attack chain | Source: Palo Alto
The attack chain | Source: Palo Alto

Proofpoint reported TA458 leveraged the SpyPress malware, obfuscated JavaScript with a version tailored to each mailserver that attempts six distinct persistence mechanisms, including reverse shells and dropped PHP webshells. 

TA458's targeting leans heavily toward Ukraine. Researchers believe the group is likely aligned with Russia’s General Staff Main Intelligence Directorate (GRU), possibly tied to the 85th Main Special Service Center (Unit 26165) or Unit 20728.

Government entities there remain the primary focus, alongside military and government installations across Albania, Greece, Moldova, and Türkiye, and financial organizations across NATO member states, Ukraine, Commonwealth of Independent States (CIS) countries, and Africa.

Last week, Dutch intelligence warned that Russian hackers are turning doorbell and security cameras into spy tools to track NATO military logistics. In May 2025, researchers reported that Void Blizzard was impersonating the European Defense & Security Summit in phishing emails.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: