
A hacking group known as APT28, sponsored by the Russian government’s military intelligence (GRU), took advantage of a weakness in Zimbra Collaboration Suite (ZCS) to attack Ukrainian government organizations.
This critical vulnerability (identified as CVE-2025-66376 and fixed in early November) is a type of cross-site scripting (XSS) that attackers who haven’t logged in can use to remotely run code, taking control of the Zimbra server and the victim’s email.
On Wednesday, the Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its list of known exploited vulnerabilities. CISA also instructed Federal Civilian Executive Branch (FCEB) agencies to patch their systems within a two-week deadline, as required by Binding Operational Directive (BOD) 22-01 issued in November 2021.
While CISA didn’t share more details about the ongoing exploitation of CVE-2025-66376, Seqrite Labs researchers reported the previous day that APT28’s military hackers had leveraged the Zimbra XSS vulnerability in assaults against Ukraine.
The Ukrainian State Hydrology Agency (a key part of infrastructure under the Ministry of Infrastructure, responsible for maritime and hydrographic services) was among the targets of this phishing campaign (dubbed Operation GhostMail).
“The phishing email doesn’t include suspicious files, malicious links, or enable macros. The entire attack sequence remains within the HTML code of one email; there are no suspect attachments,” Seqrite Labs noted.
The APT28 (also known as Fancy Bear or Strontium) hackers embedded a concealed JavaScript within their malicious emails, which takes advantage of CVE-2025-66376 when the receiver opens the email in a vulnerable Zimbra webmail session.
“The script silently executes in the user’s browser to harvest credentials, session tokens, backup 2FA codes, browser passwords, and the victim’s mailbox contents from the previous 90 days, sending the stolen data via DNS and HTTPS,” the researchers stated.
Zimbra vulnerabilities are frequently targeted, including by Russian government-backed groups, and have led to breaches of thousands of vulnerable email servers in recent years.
For example, starting in February 2023, the Russian Winter Vivern group employed another reflected XSS exploit to compromise Zimbra webmail portals and monitor NATO-affiliated organizations and individuals, including government figures, military staff, and diplomats.
In October 2024, U.S. and U.K. cybersecurity agencies also cautioned that APT29 (also called Cozy Bear or Midnight Blizzard), tied to Russia’s Foreign Intelligence Service (SVR), were broadly attacking vulnerable Zimbra servers, employing a vulnerability previously used to pilfer email account credentials.
Zimbra is a popular email and collaboration suite utilized by hundreds of millions of users, including multiple government bodies and numerous businesses globally.
#attack #government #hackers #news #russian #systems #ukrainian #used #vulnerability #zimbra — News
© Bulletproof Servers. All rights reserved.