A new cyberespionage campaign has brought back to the fore the APT28 group , also known as Fancy Bear , which is linked to the Russian military intelligence agency GRU . The attackers are exploiting a serious vulnerability in the Zimbra Collaboration Suite (ZCS) email and collaboration suite , targeting critical Ukrainian infrastructure and government organizations.

The vulnerability, recorded as CVE-2025-66376, concerns a stored cross-site scripting (XSS) flaw, which can be exploited by unauthorized users to execute remote code and completely compromise email accounts.
Urgent warning from CISA
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has listed the vulnerability as a Critically Exploited Vulnerability (KEV), underscoring its severity, and has ordered federal agencies to immediately patch their systems within two weeks, in accordance with BOD 22-01.
See also: Horabot Banking Trojan: New campaign focusing on Mexico
Although CISA did not provide details about the attacks, independent analyses confirm that the vulnerability is actively being exploited in targeted espionage operations.
Operation GhostMail: The new tactic without attachments
The campaign, which was uncovered by security researchers, is called Operation GhostMail and stands out for its originality. Unlike traditional phishing attacks, the malicious emails do not include attachments or suspicious links.
Instead, the entire attack is embedded in the HTML body of the message, via obfuscated JavaScript code. When the user opens the email in a vulnerable Zimbra webmail environment, the vulnerability is exploited without any additional action.

Silent real-time data interception
Once the malicious script is executed, a silent data collection. Attackers gain access to login credentials, session tokens, 2FA backup passwords, saved browser passwords, as well as up to 90 days of complete email history.
See also: Ubiquiti UniFi: Vulnerability allows access to accounts
Data is exfiltrated via DNS and HTTPS, making detection by conventional security systems particularly difficult.
Targeting critical infrastructure in Ukraine
The campaign targets include the State Hydrographic Service of Ukraine, an organization critical to navigation and infrastructure support. The selection of such targets suggests a clear strategic orientation towards collecting high-value information.
The targeting of government agencies and organizations related to infrastructure reinforces the assessment that this is a operation state espionage and not simply a financially motivated attack.
The timeless exploitation of Zimbra vulnerabilities
Zimbra platform vulnerabilities are a perennial target for cyber-espionage groups. In recent years, they have been repeatedly used to compromise thousands of email servers worldwide.
Notably, the Winter Vivern group exploited XSS vulnerabilities in 2023 to spy on organizations affiliated with NATO, while in 2024 APT29 launched massive attacks on vulnerable Zimbra servers, stealing user credentials.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Interlock Ransomware: Cisco FMC Zero-Day Exploit
Why webmail is an ideal target
Webmail is a key communication tool for organizations and governments, making it a particularly attractive target. Accessing an email account can reveal critical information, internal communications , and credentials for other services.
Furthermore, attacks that rely on browsers, such as this GhostMail one, bypass traditional endpoint security measures, making them harder to detect.

Need for immediate hardening and prevention
Addressing such threats requires immediate installation of security updates and strengthening of protection mechanisms against XSS attacks. Organizations should implement zero trust policies, actively monitor webmail activity, and train their staff.
The case of APT28 and Zimbra demonstrates that cyber attacks are evolving towards more «invisible» forms, where exploitation occurs without visible signs. In this environment, prevention and timely detection constitute the only effective defense.
Source: www.bleepingcomputer.com
