---
title: "Cyberespionage without a click: how Russian hackers leaked NATO data for years via a Zimbra vulnerability"
description: "Russian hackers used a Zimbra vulnerability for over a year to spy on NATO and Ukraine. To hack the system, it was enough to simply open an email — no clicks were required. After being exposed, the TA488 group destroyed its infrastructure and disappeared 🕵️‍♂️💻🚫"
date: 2026-07-27T09:16:00.000Z
lang: en
url: https://xab.info/en/posts/cyberespionage-without-a-click-russian-hackers-zimbra-vulnerability-nato
tags: [zimbra, nato, ukraine, ta488, cybersecurity]
publisher: "XAB.info"
---

# Cyberespionage without a click: how Russian hackers leaked NATO data for years via a Zimbra vulnerability

![Silhouette of a person with red digital code on the background, symbolizing cyber espionage and data leaks through Zimbra vulnerability](https://xab.info/media/2026/07/27/russian-hackers-zimbra-vulnerability-nato-espionage/russian-hackers-zimbra-vulnerability-nato-espionage-1.webp)

### Large-scale cyberespionage campaign exploiting a Zimbra vulnerability

Cybersecurity experts from Proofpoint have revealed details of a large-scale cyberespionage campaign conducted by Russian hacker groups for over a year. At the center of the incident was a critical vulnerability in the popular Zimbra email platform, which allowed attackers to access confidential information without the active participation of the victim.

The main targets of the attacks included military departments and government agencies of NATO countries, as well as key organizations in Ukraine. Hackers paid special attention to enterprises in the defense industry, seeking to steal strategically important data.

### "Half-click" technology: infection without user action

The uniqueness of the method used lies in its effectiveness and stealth. Experts classified the attack as a *half-click exploit*. This means that for a successful system infection, the victim did not need to perform any active actions: clicking links, opening attachments, or downloading files.

The attack was executed via a cross-site scripting (XSS) vulnerability in the Zimbra web interface. It was sufficient for the user to simply open an incoming email and view its contents for the malicious code to activate and grant hackers full access to the computer.

### Vulnerability details and developer response

The security issue received the official identifier CVE-2025-66376 and a severity score of 7.2 out of 10, classifying it as a high-risk level. Although developers released a fix for the system in November 2025, Russian groups had been exploiting this breach long before the official patch was released.

Analysts note that the vulnerability was used by various hacker groups for an extended period. However, within the framework of the investigated campaign, the activity of a specific group, TA488, was recorded. This group is known in the cybersecurity community by the aliases *Laundry Bear* and *Void Blizzard*.

### Operational methods and infrastructure dismantling

After successfully penetrating the victim's network, hackers from TA488 installed backdoors to maintain persistent access and began systematic data collection. The regularity of attacks on government structures indicates long-term planning and high organization within the group.

However, the activity of the TA488 group has likely ceased. Security researchers have recorded no actions from the hackers since February 2026. The disappearance of the group coincided with the publication of a detailed analysis of their infrastructure and methods by specialists from Seqrite.

The published analysis was so comprehensive that it forced Russian hackers to completely destroy their servers and communication networks, shutting down operations to avoid further identification and prosecution.