Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
Russian state-supported actors are utilizing a Zimbra zero-day exploit to steal emails and 2FA codes from Western organizations.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
Russian espionage group TA488 has deployed 'zero-click' and 'half-click' phishing campaigns targeting Zimbra mailservers. These operatives have successfully stolen emails and two-factor authentication (2FA) codes without relying on traditional social engineering.
Coverage from the National Cyber Security Centre, Reuters, and CNN emphasizes that the targets include US nuclear scientists and defense contractors. Proofpoint and The Hacker News identify the specific technical vector as a zero-day exploit affecting Zimbra infrastructure.
Future developments depend on the efforts of the UK and its partners to expose these state-supported actors and the subsequent response to the identified vulnerabilities.
Synthesized by Archynetys from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated just now.
Quick answers
Who is the primary actor behind these attacks?
The attacks are attributed to Russian state-supported actors, specifically identified by Proofpoint as TA488.
What specific technology was exploited?
The group exploited a zero-day vulnerability in Zimbra mailservers.
Which specific targets have been identified?
According to CNN, targets include US defense contractors and nuclear scientists.
Coverage (5)
- UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations National Cyber Security Centre · 17h ago
- US and allies say Russian hackers stole emails without social engineering Reuters · 17h ago
- New warnings that Russian operatives are targeting the emails of US nuclear scientists and defense contractors CNN · 17h ago
- TA488 Targets Zimbra Mailservers with Half-Click Exploits Proofpoint · 17h ago
- Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes The Hacker News · 17h ago
Topics
Related trends
The West's plan to pressure Putin has a glaring flaw
Western strategies to pressure Vladimir Putin face critical challenges amid shifts in Ukraine's military tactics and leadership.
Has Russia helped Iran target CIA sites in the Gulf?
U.S. authorities are investigating whether Russian technology aided Iranian strikes on CIA facilities in the Gulf.
Crimea Comes Under Another Night of Drone Strikes
Ukraine has launched a wave of drone strikes across Crimea and southern Russia, disrupting critical infrastructure and causing casualties.
Russia strips rights of citizens abroad in sweeping new 'traitor' law
Russia has passed 'civil death' legislation targeting exiled critics by freezing assets and blocking essential consular services.
Lavrov tells Rubio 'unacceptable' for US to continue arms sales to Kyiv
Tensions persist as Russian and U.S. officials meet amid conflicting views on arms sales and the path toward ending the war in Ukraine.
EU agrees 21st sanctions package against Russia after Greece drops veto
The EU has finalized its 21st sanctions package against Russia after Greece dropped its veto following an agreement on LNG exemptions.