Zero‑Click Phishing Exploits Zimbra CVE‑2025‑66376, Exfiltrating Email Data Across Government and Finance Sectors
What Happened – Unit 42 tracked a nation‑state espionage campaign (CL‑STA‑1114) that leverages a zero‑click phishing email to exploit CVE‑2025‑66376 in the Zimbra Collaboration Suite (ZCS). The malicious JavaScript payload is injected automatically, stealing credentials, 2FA scratch codes, CSRF tokens, and up to 90 days of email/search history from targeted Zimbra servers.
Why It Matters for Compliance & Audit Readiness
- The attack bypasses user interaction, exposing gaps in SOC 2 Access Control testing and the need for continuous monitoring of credential‑related controls.
- Successful exfiltration of email archives can trigger privacy‑related audit findings (e.g., GDPR/CCPA) if personal data is not adequately protected.
- Demonstrates the importance of Security Awareness Training that includes zero‑click phishing scenarios and verification of patch management processes.
Who Is Affected – Government agencies, defense ministries, transportation operators, and financial institutions that run unpatched Zimbra webmail installations in NATO, Ukraine, CIS, and African regions.
Recommended Actions
- Apply the Zimbra security patch for CVE‑2025‑66376 immediately.
- Deploy advanced email security (sandboxing, URL/attachment inspection) and enforce MFA for all webmail accounts.
- Incorporate zero‑click phishing simulations into your Security Awareness program and document evidence for SOC 2 audit controls.
Technical Notes – The exploit uses a Base64‑obfuscated SVG element that decodes to JavaScript, which runs in the victim’s browser without any click. Data exfiltrated includes CSRF tokens, credentials, 2FA scratch codes, system details, and recent email/search history. Source: Palo Alto Unit 42