Proofpoint
Russian TA488 and TA458 Exploit Webmail Vulnerabilities in Espionage Campaigns
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Russian threat actors TA488 and TA458 are exploiting vulnerabilities in webmail servers, specifically targeting Ukrainian entities and government sectors. TA488 utilizes a half-click exploit via CVE-2025-66376 in Zimbra mailservers, allowing immediate execution of malicious scripts upon email preview. This actor has been active since July 2025, using compromised accounts to send exploit-laden messages. Meanwhile, TA458 has been exploiting a zero-day vulnerability in the SOGo webmail platform, reported as CVE-2026-8496, targeting military and government entities across Eastern Europe. Both actors employ techniques that require minimal user interaction, increasing the risk of successful attacks. The campaigns are part of a broader trend of Russian cyber espionage activities, with significant implications for national security.
Key Points: • TA488 exploits CVE-2025-66376 in Zimbra webmail, enabling immediate script execution. • TA458 targets SOGo webmail with a zero-day vulnerability, CVE-2026-8496, affecting Eastern European entities. • Both actors utilize half-click exploits, minimizing user interaction and increasing attack success rates.