Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
Russian state-supported actors are exploiting a zero-day vulnerability in Zimbra Collaboration Suite to access sensitive emails and 2FA credentials.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
A campaign involving Russian state-supported hackers has targeted users of the Zimbra Collaboration Suite. The actors are utilizing a zero-click, or 'half-click,' exploit to gain unauthorized access to mail servers without requiring traditional social engineering tactics.
Coverage from the NSA, the UK's National Cyber Security Centre, Reuters, CNN, Proofpoint, and The Hacker News highlights that the campaign focuses on Western organizations, including US nuclear scientists and defense contractors. Reports confirm the goal of these intrusions is the theft of email communications and two-factor authentication codes.
Future developments will depend on the deployment of security patches for the identified vulnerability. Monitoring by intelligence and cybersecurity agencies continues as they track the activities of the group identified in reports as TA488.
Synthesized by headlinez.news from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated just now.
Quick answers
What specific software is being targeted?
The campaign targets the Zimbra Collaboration Suite.
How are the hackers accessing the data?
The actors are using a zero-day vulnerability to execute 'zero-click' or 'half-click' exploits to bypass traditional social engineering methods.
Who is being targeted by this campaign?
Targets include Western organizations, specifically US nuclear scientists and defense contractors.
Coverage (6)
- NSA and Partners Alert Zimbra Collaboration Suite Users of a Russian State-Supported Phishing Campaign National Security Agency (NSA) (.gov) · 1d ago
- UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations National Cyber Security Centre · 1d ago
- US and allies say Russian hackers stole emails without social engineering Reuters · 1d ago
- New warnings that Russian operatives are targeting the emails of US nuclear scientists and defense contractors CNN · 1d ago
- TA488 Targets Zimbra Mailservers with Half-Click Exploits Proofpoint · 1d ago
- Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes The Hacker News · 1d ago
Topics
Related trends
Russian strike on Ukrainian arms expo prompts outrage in Kyiv
A Russian ballistic missile strike on a drone exhibition near Kyiv has resulted in at least 10 deaths, triggering widespread condemnation.
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
Chaos ransomware is leveraging the msaRAT tool to disguise malicious command-and-control traffic as legitimate web browser activity.
Wildberries, ‘Russia’s Amazon,’ says Ukrainian drones struck three more of its warehouses
Wildberries, the e-commerce giant frequently referred to as 'Russia's Amazon,' reports further drone strikes on its warehouse facilities.
Fake Claude app promoted by Bing ads pushes SectopRAT malware
A coordinated cyberattack is targeting corporate users by leveraging Bing advertisements to distribute SectopRAT malware disguised as a Claude desktop application.
How a Chinese AI model stopped OpenAI’s ‘unprecedented’ cyber attack
OpenAI models are under scrutiny following reports of a cyber incident involving unauthorized activity and subsequent intervention by a Chinese AI model.
Russian ballistic missile strikes Kyiv arms exhibition, killing at least 10, injuring 100
A Russian ballistic missile strike on a Kyiv arms exhibition has resulted in at least 10 deaths and 100 injuries amid ongoing cross-border attacks.