ctipilot.ch
← Back to Weekly 2026-W30
HIGHexploitedNATOA1synthesis

Self-hosted webmail is a standing state-espionage battleground — this week a 16-nation advisory exposed Russia's LAUNDRY BEAR Zimbra zero-click and Proofpoint detailed a separate GRU actor's live 'half-click' zero-day supply across five webmail platforms

discovered 2026-07-26 23:41 UTCrun 2026-07-26T2309Z-weekly5 sourcesmulti-source

If you did nothing this week: any internet-reachable self-hosted webmail server in your estate — Zimbra above all, but also SOGo, Roundcube, mDaemon or Kerio — is exposed to at least one Russian state actor running exploits that compromise a mailbox the instant a targeted user simply opens a message, with no link to click and no attachment to open.

Two independent disclosures made webmail the week's espionage story, and they are two different actors. The 16-nation joint advisory AA26-204A attributes a sustained campaign against Zimbra Collaboration Suite to LAUNDRY BEAR (also tracked as Void Blizzard / TA488), and describes its distinguishing tradecraft precisely: the campaign "leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service" (joint CSA AA26-204A, 2026-07-23), abusing the stored-XSS CVE-2025-66376 to steal 90 days of mail, the Global Address List and 2FA codes (joint CSA AA26-204A, 2026-07-23). Proofpoint's follow-up added the mechanics the advisory omitted, including a CSS-@import sanitizer bypass that reassembles an executing <svg onload="eval(atob('…'))"> and — the part that matters for eviction — the creation of an attacker-controlled application-specific password as a persistence credential separate from the user's own login (Proofpoint, 2026-07-23).

The second actor is TA458 (ESET's Operation RoundPress), which Proofpoint assesses as a likely Russian GRU operation and — importantly — states it "has not observed TA458 using CVE-2025-66376" (Proofpoint, 2026-07-23), keeping the two clusters distinct. TA458 instead runs a standing supply of "half-click" webmail zero-days that fire the instant a target opens a message across Zimbra, mDaemon, Roundcube, Kerio and — newly disclosed this week — SOGo, where Proofpoint reported the flaw to Alinto and it "was patched as CVE-2026-8496 in version 5.12.8" (Proofpoint, 2026-07-23), each dropping a per-client SpyPress payload to steal credentials, contacts and mail. That the same week also brought a routine Zimbra 10.1.20 release fixing an SNMP command-injection RCE and four stored-XSS bugs underlines how continuously this software surface turns over.

Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, LAUNDRY BEAR's latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service.

CISA / NSA / FBI + allied agencies from 16 nations (joint CSA AA26-204A) 2026-07-23

A 'half-click exploit' requires no social engineering, nor does it require a user to click a link or open an attachment. The targeted user must only open the malicious email in their webmail viewer to be compromised.

Proofpoint has not observed TA458 using CVE-2025-66376, despite the group's regular access to webmail XSS zero-days.

Proofpoint Threat Research 2026-07-23

ATT&CK mapping

7 techniques mapped from the cited reporting · MITRE ATT&CK v19.1

Initial Access TA0001
T1566Phishing

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

overlap matrix · ATT&CK page ↗

Execution TA0002
T1203Exploitation for Client Execution

Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility.

overlap matrix · ATT&CK page ↗

Persistence TA0003
T1098Account Manipulation

Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.

overlap matrix · ATT&CK page ↗

T1556.006Modify Authentication Process: Multi-Factor Authentication

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

overlap matrix · ATT&CK page ↗

Privilege Escalation TA0004
T1098Account Manipulation

Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.

overlap matrix · ATT&CK page ↗

Defense Impairment TA0112
T1556.006Modify Authentication Process: Multi-Factor Authentication

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

overlap matrix · ATT&CK page ↗

Credential Access TA0006
T1539Steal Web Session Cookie

An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website.

overlap matrix · ATT&CK page ↗

T1556.006Modify Authentication Process: Multi-Factor Authentication

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

overlap matrix · ATT&CK page ↗

Discovery TA0007
T1087.003Account Discovery: Email Account

Adversaries may attempt to get a listing of email addresses and accounts. Adversaries may try to dump Exchange address lists such as global address lists (GALs).

overlap matrix · ATT&CK page ↗

Collection TA0009
T1114.002Email Collection: Remote Email Collection

Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Adversaries may leverage a user's credentials and interact directly with the Exchange server to acquire information from within a network. Adversaries may also access externally facing Exchange services, Office 365, or Google Workspace to access email using credentials or access tokens. Tools such as MailSniper can be used to automate searches for specific keywords.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.