Text size:
The Scam Exposed
Scam Alerts

UK and Partners Warn: Russian Hackers Using Zero-Click Phishing to Steal Emails from Zimbra Users

By ScamGuard Team · · 5 min read
UK and Partners Warn: Russian Hackers Using Zero-Click Phishing to Steal Emails from Zimbra Users

UK and partners recently exposed a new "zero-click phishing" campaign. This post explains the incident clearly so you and your family can understand the risk, spot warning signs, and take simple steps to stay safe.

What happened? (Simple summary)

  • The UK National Cyber Security Centre (NCSC) and international partners (including the US NSA, CISA, FBI, DoD, and 15 other countries) identified a Russian state-supported group called LAUNDRY BEAR (also known as Void Blizzard) running a zero-click phishing campaign.

  • The attacks targeted organizations in Western countries, including government, defense, education, energy, law enforcement, media, non-governmental organizations, and technology sectors.

  • The attackers used specially crafted emails to users of Zimbra Collaboration Suite (ZCS) webmail. Victims could be affected just by viewing a malicious email in a vulnerable Zimbra webmail system, without clicking any links or opening attachments.

  • This campaign has been active since around July 2025, and the advisory was published in July 2026.

What is "zero-click phishing"? (Very simple)

  • Normal phishing tricks you into clicking a link, opening an attachment, or giving a password.

  • Zero-click phishing can harm your device or data just by sending a message that the device or system processes automatically, like a malicious email that runs code when you view it.

  • That means you could be affected even if you do not open anything.

  • In this case, the flaw is a stored cross-site scripting (XSS) vulnerability in Zimbra webmail, tracked as CVE-2025-66376.

How the attack works (Easy flow)

  • The attacker sends a specially crafted email to users of Zimbra webmail.

  • When the victim views the malicious email in a vulnerable Zimbra webmail interface, the browser runs a malicious JavaScript payload without any click.

  • This exploit uses a zero-day vulnerability in Zimbra, tracked as CVE-2025-66376.

  • The script steals the victim's session token (ZMBAuthToken), CSRF tokens, 2FA codes, email addresses, passwords, Global Address List (GAL), and up to 90 days of email history.

  • Attackers then try to steal information, access accounts, or keep control of the system.

  • The stolen data is sent over DNS and HTTPS to attacker-controlled servers using a tool called "Flowerbed" or "Ulej".

Who is most at risk?

  • Organizations with sensitive information: government offices, non-profits, media, and legal firms.

  • People involved in politics, activism, or foreign affairs.

  • Organizations that use Zimbra Collaboration Suite (ZCS) webmail and have not applied security updates are the main target.

  • Users with old phones or computers that are no longer receiving software updates. Note for older adults: if your device is old and not updated, the risk is higher.

  • The group initially targeted cloud environments in Ukraine before expanding to Western targets in various industrial sectors.

Warning signs to watch for

  • Your phone or computer suddenly becomes very slow.

  • Apps crash or show strange messages.

  • Battery drains faster than normal.

  • Contacts tell you they received strange messages from your account.

  • Unknown logins or security alerts from your email or other services.

  • Unusual DNS traffic or HTTPS connections to unknown servers.

Immediate steps to take

  1. If you see a suspicious message, turn on airplane mode or disconnect the device from the internet.

  2. Do not open attachments or view media previews from unknown senders. Delete the message.

  3. Update your device and apps right away: go to settings and install software updates.

  4. Restart your device. If the strange behavior continues, keep the device offline and ask an expert for help.

  5. Change passwords for email, bank, and important accounts from a safe device. Use strong passwords.

  6. Turn on two-factor authentication (2FA) for important accounts, using an authenticator app if possible.

  7. Contact your bank or important services if you think financial information may be exposed.

  8. If you work for an organization, inform your IT or security team immediately.

  9. If your organization uses Zimbra webmail, apply the latest security updates immediately and check for signs of compromise.

  10. Monitor for unusual activity in email accounts and network logs.

Long-term safety tips

  • Always install software updates. Updates fix security problems and are the best defense.

  • Use two-factor authentication for accounts. Authenticator apps are safer than SMS.

  • Replace very old devices that do not get updates.

  • Install apps only from official stores and avoid unknown attachments.

  • Keep regular backups of important files to an external drive or a trusted cloud service.

  • Teach family members and caregivers simple rules: do not open unexpected attachments and always verify messages by phone if unsure.

For organizations (short checklist)

  • Share threat information and watch for indicators provided by authorities like NCSC, CISA, and NSA.

  • Strengthen email filtering and network defenses.

  • Use endpoint protection tools and review system logs.

  • Make sure there is an incident response plan and clear isolation procedures.

  • Patch Zimbra Collaboration Suite to the latest version and review logs for suspicious activity related to CVE-2025-66376.

  • Watch for domains impersonating Zimbra infrastructure, such as "mailnalysis.com", "emailanalytics.com.ua", "zimbrastat.com", "zimbra-metadata.com", "istc-cloud.com", and "zmailanalytics.com".

  • Monitor for unusual DNS queries and HTTPS traffic to unknown servers.

 

You're Safe Here. Let's Fix This Now.

If you already sent money or shared information, act fast. Follow these steps in order.

1

Call Your Bank or Card Company Immediately

Use the number on the back of your card, not any number the caller gave you. Ask them to freeze the transaction or account.

2

Call the National Elder Fraud Hotline

Free help, 7 days a week.

Call 1-833-372-8311
3

Report It to the Government

File a free report at the Federal Trade Commission so they can investigate.

Go to reportfraud.ftc.gov