HomeSecurityRussian hackers target Ukraine via Zimbra vulnerability

Russian hackers target Ukraine via Zimbra vulnerability

A new cyberespionage campaign has brought back to the fore the APT28 group , also known as Fancy Bear , which is linked to the Russian military intelligence agency GRU . The attackers are exploiting a serious vulnerability in the Zimbra Collaboration Suite (ZCS) email and collaboration suite , targeting critical Ukrainian infrastructure and government organizations.

Russian hackers Zimbra

The vulnerability, recorded as CVE-2025-66376, concerns a stored cross-site scripting (XSS) flaw, which can be exploited by unauthorized users to execute remote code and completely compromise email accounts.

Urgent warning from CISA

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has listed the vulnerability as a Critically Exploited Vulnerability (KEV), underscoring its severity, and has ordered federal agencies to immediately patch their systems within two weeks, in accordance with BOD 22-01.

See also: Horabot Banking Trojan: New campaign focusing on Mexico

Although CISA did not provide details about the attacks, independent analyses confirm that the vulnerability is actively being exploited in targeted espionage operations.

Operation GhostMail: The new tactic without attachments

The campaign, which was uncovered by security researchers, is called Operation GhostMail and stands out for its originality. Unlike traditional phishing attacks, the malicious emails do not include attachments or suspicious links.

Instead, the entire attack is embedded in the HTML body of the message, via obfuscated JavaScript code. When the user opens the email in a vulnerable Zimbra webmail environment, the vulnerability is exploited without any additional action.

Russian hackers target Ukraine via Zimbra vulnerability

Silent real-time data interception

Once the malicious script is executed, a silent data collection. Attackers gain access to login credentials, session tokens, 2FA backup passwords, saved browser passwords, as well as up to 90 days of complete email history.

See also: Ubiquiti UniFi: Vulnerability allows access to accounts

Data is exfiltrated via DNS and HTTPS, making detection by conventional security systems particularly difficult.

Targeting critical infrastructure in Ukraine

The campaign targets include the State Hydrographic Service of Ukraine, an organization critical to navigation and infrastructure support. The selection of such targets suggests a clear strategic orientation towards collecting high-value information.

The targeting of government agencies and organizations related to infrastructure reinforces the assessment that this is a operation state espionage and not simply a financially motivated attack.

The timeless exploitation of Zimbra vulnerabilities

Zimbra platform vulnerabilities are a perennial target for cyber-espionage groups. In recent years, they have been repeatedly used to compromise thousands of email servers worldwide.

Notably, the Winter Vivern group exploited XSS vulnerabilities in 2023 to spy on organizations affiliated with NATO, while in 2024 APT29 launched massive attacks on vulnerable Zimbra servers, stealing user credentials.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Interlock Ransomware: Cisco FMC Zero-Day Exploit

Why webmail is an ideal target

Webmail is a key communication tool for organizations and governments, making it a particularly attractive target. Accessing an email account can reveal critical information, internal communications , and credentials for other services.

Furthermore, attacks that rely on browsers, such as this GhostMail one, bypass traditional endpoint security measures, making them harder to detect.

Russian hackers target Ukraine via Zimbra vulnerability

Need for immediate hardening and prevention

Addressing such threats requires immediate installation of security updates and strengthening of protection mechanisms against XSS attacks. Organizations should implement zero trust policies, actively monitor webmail activity, and train their staff.

The case of APT28 and Zimbra demonstrates that cyber attacks are evolving towards more «invisible» forms, where exploitation occurs without visible signs. In this environment, prevention and timely detection constitute the only effective defense.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS