← Back to blog

Russian Hackers Exploit Zimbra Zero-Day to Steal Emails and 2FA Codes

A Russian state-sponsored group used a previously unknown Zimbra vulnerability to access sensitive emails and bypass two-factor authentication. The attack highlights critical risks in enterprise webmail systems.

TL;DR

  • Russian espionage group targeted Western organizations using a Zimbra zero-day exploit.
  • The attack silently harvested 90 days of emails, contact directories, and stored passwords.
  • Malicious emails triggered the payload automatically, stealing 2FA recovery codes.
  • NSA and CISA jointly disclosed the vulnerability and issued mitigation guidance.
  • Organizations using Zimbra should immediately review logs and update affected systems.

A sophisticated Russian state-backed hacking operation has been uncovered exploiting a zero-day vulnerability in Zimbra's webmail client. The breach allowed attackers to silently access sensitive corporate communications and undermine two-factor authentication protections.

Security agencies including the NSA and CISA have confirmed that the threat actors gained persistent access to target mailboxes, exfiltrating up to three months of email history along with critical authentication data. The exploitation required no user interaction beyond opening a specially crafted message.

Attack Vector and Impact

  • The zero-day flaw existed in Zimbra's Collaboration Suite webmail interface.
  • Opening a malicious email was sufficient to trigger the stealthy payload.
  • Attackers extracted 90 days of email content, full organizational directories, and browser-stored credentials.
  • Two-factor authentication was bypassed by stealing recovery codes stored within the compromised sessions.

Defense Recommendations

  • Organizations should audit Zimbra installations for signs of compromise using indicators released by CISA.
  • Immediate patching is advised where updates are available from Zimbra.
  • Administrators should rotate 2FA secrets and revoke existing session tokens for all users.
  • Enhanced logging and monitoring should be enabled to detect similar future intrusions.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Russian Hackers Exploit Zimbra Zero-Day to Steal Emails and 2FA Codes — Agent Breach Blog | Agent Breach