Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-catalogstate-sponsored-espionagephishing-campaign-intelligence

APT28 Exploits Zimbra XSS Flaw to Breach Ukrainian Government Webmail

Updated 3mo agoFirst seen Mar 19, 20268 sources

APT28, the Russia-linked threat group associated with the GRU, used a phishing campaign dubbed Operation GhostMail to target Ukrainian government entities by exploiting Zimbra Collaboration Suite vulnerability CVE-2025-66376. The campaign targeted the State Hydrographic Service of Ukraine, a critical infrastructure body supporting maritime navigation and hydrographic operations. The attack used a single email written in Ukrainian and disguised as a routine internship inquiry; instead of relying on attachments or links, the malicious payload was embedded directly in the HTML body and executed when opened in a vulnerable Zimbra webmail session.

Researchers said the stored XSS flaw allowed attackers to run obfuscated JavaScript in the victim’s browser, enabling theft of login credentials, session tokens, backup two-factor authentication codes, browser-stored passwords, and up to 90 days of mailbox data. Reporting also notes the flaw was patched in November and later added by CISA to its Known Exploited Vulnerabilities catalog, with U.S. federal civilian agencies ordered to remediate within two weeks under BOD 22-01. The operation stood out for abusing a trusted webmail environment to hijack authenticated sessions without deploying traditional malware, helping the intrusion evade many standard phishing and endpoint defenses.

Share:
APT28 Exploits Zimbra XSS Flaw to Breach Ukrainian Government Webmail
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Mar 19, 20263mo ago

CISA adds CVE-2025-66376 to KEV catalog

CISA added CVE-2025-66376 to its Known Exploited Vulnerabilities catalog after the flaw was observed in active exploitation. The agency ordered U.S. federal civilian agencies to remediate affected Zimbra servers within two weeks, with reporting citing an April 1, 2026 deadline.

Zimbra patches CVE-2025-66376 in supported releases

Synacor released fixes for CVE-2025-66376 in Zimbra versions 10.1.13 and 10.0.18. The vulnerability involved insufficient sanitization of CSS @import directives in Classic UI, enabling attacker-controlled JavaScript execution when a victim opened a malicious email.

APT28 linked to exploitation of Zimbra flaw CVE-2025-66376

Seqrite Labs attributed the campaign with medium confidence to APT28, the GRU-linked group also known as Fancy Bear. The attackers exploited the stored XSS flaw CVE-2025-66376 in Zimbra Classic UI to steal credentials, session tokens, backup 2FA codes, browser-saved passwords, and up to 90 days of mailbox data.

Operation GhostMail targets Ukrainian government via Zimbra phishing

A Russian espionage campaign later tracked as Operation GhostMail targeted Ukrainian government entities, including the State Hydrographic Service/State Hydrology Agency and a national maritime agency, using Ukrainian-language phishing emails. The emails embedded the full exploit chain in HTML content, requiring no attachment or link.

Jan 20, 20265mo ago

GhostMail command-and-control domains established

Researchers reported that two command-and-control domains used in the Zimbra exploitation campaign were set up on January 20, 2026. This infrastructure later supported the Ukraine-targeted phishing and data-exfiltration activity tied to Operation GhostMail.

Russian APT weaponizes critical Zimbra bug in Ukraine-targeted intrusions | brief | SC Media
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

9 LINKEDOpen in app
Threat actors
3 linked
Affected products
2 linked
Zimbra CollaborationZimbra Collaboration Suite
Organizations
3 linked
ZimbraSecurity AffairsSeqrite
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

APT28 Exploits Zimbra XSS Flaw to Breach Ukrainian Government Webmail | Mallory