Zimbra caught in Russian espionage

Do you know if your corporate email is being emptied right now by Russian spies?
Russia has been stealing entire Zimbra mailboxes for months without anyone noticing.
Unit 42 has identified CL-STA-1114, linked to Void Blizzard, active since 2024 and directly targeting Zimbra since July 2025.
The method is so silent that you don’t need to open any attachment: as soon as the email appears on screen, the theft has already begun.

A single email is enough to lose absolutely everything.
The trap arrives as an email with news headlines designed to catch your attention. Inside, hidden in the HTML, there is Base64-encoded code that the browser executes when loading the message. That code creates an invisible SVG element that injects a JavaScript payload into your Zimbra session. You don’t need to do anything: as soon as the email is displayed, the exploit has already launched.
The payload acts before you can react.
Once executed, the JavaScript payload connects to a hardcoded command-and-control server and exfiltrates credentials, mailbox files, and search history. The servers rotate frequently: at least nine different IPs and nine different domains, active for an average of 35 days before being replaced, making it nearly impossible to block them in time.
CVE-2025-66376 continues to be actively exploited on unpatched Zimbra servers worldwide.
The most concerning aspect is that the attackers have barely modified their JavaScript payload since the campaign began: they don’t need to innovate because the vulnerability remains open in too many installations. As long as instances of Zimbra Collaboration Suite exist without the patch applied, CL-STA-1114 has free rein to keep harvesting credentials.

This is not an isolated or one-off case.
CL-STA-1114 targets critical sectors across multiple countries using the same rotating infrastructure and the same zero-click phishing.
Zero-click phishing eliminates the human link, rendering traditional security awareness training useless.
The campaign used nine IPs and nine C2 domains, each active for approximately 35 days — far too short a window for blocklists.
Patching is no longer optional: it is urgent.
When a state actor can empty your mailbox without you lifting a finger, the window to act is minimal. Zimbra administrators must apply the CVE-2025-66376 patch immediately and review the indicators of compromise published by Unit 42.
State-sponsored espionage has changed in scale.
Void Blizzard is not an opportunistic group: it is a persistent operation with the resources to maintain rotating infrastructure for months. Other vendors also track it as LAUNDRY BEAR, confirming that multiple intelligence teams have been following its activity for some time. Campaigns like CL-STA-1114 demonstrate that espionage via corporate webmail has become a preferred avenue over noisier network intrusions.
Webmail is the new perimeter that no one monitors properly.
Organizations invest in protecting endpoints and firewalls, but webmail falls outside the most rigorous threat models. Zimbra is popular among public administrations and mid-sized companies, making it a target with a high density of potential victims and weaker security coverage.

The published IoCs are your first line of defense today.
Unit 42 has published the IP addresses and domains used by CL-STA-1114. Cross-referencing those indicators against your Zimbra access logs can reveal whether you have already been compromised before any official alert reaches you.
Acting late here has real consequences.
The exfiltrated data includes active credentials, meaning an attacker who has already passed through your server can reuse those keys on other internal systems. The damage is not limited to the mailbox: it is the entry point to everything that user can access within your organization.
The patch exists. The excuse does not.
CVE-2025-66376 has a fix. Every day that passes without applying it is one more day that CL-STA-1114 may be extracting data from your organization without making any noise.
What to do now
- ✓Apply the CVE-2025-66376 patch on your Zimbra servers now.
- ✓Cross-reference Unit 42’s IoCs against your access logs.
- ✓Look for outbound connections to CL-STA-1114’s C2 domains.
Can I find out today whether my Zimbra was already compromised?
Security is not improvised, it is audited. At Nacata Security we detect vulnerabilities and protect your company, because a single flaw can cost you everything you have built.
Related articles
Nacata Security, reach out to us anytime
We are Nacata Security, get to know us
web: nacata.io
email: info@nacata.io
Phone: 919930793
LinkedIn: Nacata Security
Risks and attacks happening right now: vulnerabilities being actively exploited, official alerts from cybersecurity agencies, ongoing phishing or malware campaigns.
Information meant to help you act and protect yourself before the problem reaches you.
RATING
9.7
Who are we?
At Nacata Security we are an offensive cybersecurity company specialized in audits and penetration testing.
We detect, assess and help mitigate the vulnerabilities of your systems, networks and applications before a real attacker exploits them, offering 360º defense tailored to each client.
We’d be glad to get in touch with you for whatever you need.




