APT28 Exploits Zimbra Vulnerability in Ongoing Attacks Against Ukraine
Article Content
- •APT28 is exploiting CVE-2025-66376 in attacks against Ukrainian government entities.
- •CISA has mandated U.S. federal agencies to secure Zimbra servers by April 1, 2026.
- •Phishing emails with obfuscated JavaScript payloads are the primary attack vector.
Russian state-backed hackers from APT28 are actively exploiting a high-severity stored cross-site scripting vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite (ZCS) to target Ukrainian government entities. The flaw allows unauthenticated attackers to execute remote code and harvest sensitive information from compromised email accounts. The Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog and mandated that U.S. federal agencies secure their servers by April 1, 2026. The attacks involve phishing emails containing obfuscated JavaScript payloads that exploit the vulnerability when opened in a vulnerable Zimbra session. This campaign, named Operation GhostMail, has already targeted critical infrastructure, including the Ukrainian State Hydrology Agency. Security researchers have noted that Zimbra vulnerabilities have been frequently exploited in recent years, with multiple incidents reported involving state-sponsored actors. Organizations using Zimbra are urged to apply the available patches immediately to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (8)
Following this threat?
Track APT28, Synacor and CVE-2025-27915 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Trellix Reports on Five Evasive Cyber Campaigns in 2026 Trellix's SecondSight Threat Hunting Report details five significant cyber campaigns from the first half of 2026, including APT28 and the Axios npm supply chain attack. Attackers exploited trusted infrastructures and employed advanced evasion techniques, such as using compromised government accounts and weaponizing…
2026 AV-Comparatives EPR Test Results Released AV-Comparatives published the results of its 2026 Endpoint Prevention and Response (EPR) Test, evaluating 14 enterprise security products against 50 multi-stage attack scenarios. The test, which ran from May to August 2026, incorporated AI-assisted techniques and followed the MITRE ATT&CK framework. Eleven products…