# Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

> **Newsylist Open Intelligence Dossier** · First detected: 2026-07-24 11:29 UTC · Category: World · Sources: 6 · Current Velocity: 3.67

## Executive Summary
Security agencies report a Russian-backed group is utilizing a zero-day exploit in Zimbra software to compromise email accounts and capture 2FA codes.

## Intelligence Brief
A state-supported Russian hacking group is exploiting a vulnerability in the Zimbra Collaboration Suite. This &amp;#039;zero-click&amp;#039; or &amp;#039;half-click&amp;#039; method allows the attackers to intercept emails and two-factor authentication codes without requiring traditional social engineering tactics.


Coverage from the National Security Agency (NSA), the UK National Cyber Security Centre, Reuters, CNN, Proofpoint, and The Hacker News highlights that this campaign specifically targets Western organizations, including US defense contractors and nuclear scientists. These entities are alerting users to the sophisticated nature of these intrusions.


Future developments depend on security patches and further analysis of the TA488 group&amp;#039;s activities. Current coverage does not yet specify the full scale of the breach or the specific timeline for the remediation of affected mailservers.

## Verified Facts & Key Claims
### What software is affected by this vulnerability?
The Zimbra Collaboration Suite is the software currently identified as being targeted by this exploit.

### How do the attackers access the accounts?
The group uses 'zero-click' or 'half-click' exploits to compromise accounts, bypassing the need for traditional social engineering.

### Which groups are identified as targets?
Coverage notes that Western organizations, specifically US defense contractors and nuclear scientists, are being targeted.

## Key People, Organizations & Locations
Russian, Western, Russian Espionage Group Exploited Zimbra Zero-Day, Steal Mail, Codes, TA488 Targets Zimbra Mailservers, Half-Click Exploits, NSA and Partners Alert Zimbra Collaboration Suite Users, Russian State-Supported Phishing Campaign

## Multi-Source Evidence Table
| Source Outlet | Headline | Published (UTC) | Verification URL |
|---|---|---|---|
| National Security Agency (NSA) (.gov) | NSA and Partners Alert Zimbra Collaboration Suite Users of a Russian State-Supported Phishing Campaign | 2026-07-23 18:36 | [Source Link](https://news.google.com/rss/articles/CBMiggJBVV95cUxOdmNkQ1ltemE0X0FPTDdxaHRmRVVFQVdIbDJmQXJuYTVOeVhLcHc5bzM4RXRLSU5RamZfc29NYnVtandQM0lKTFhtWUNjVVBNMTV3eW9ON0FISnNiZGV4cDVtc29NR2w3UHR3aWowTGQzMkJ6dHFTLXhkMkJ4NlVkaVhNbHZ2WGE5NmV5THh6V190VWpFbnM4STFPejBlTEh5a0xWU3AzemFQTTRKZE05eUNETlhEWVZ6TUJub1drVDhCYjRzRDV6bUIteVNfZkhZN0hUenR2YmRpMDY1eTNsdUVRaUZGRkN0bWRpdFRzSmlGZ0gxaXdGN2hwN3lQdEFyUVE?oc=5) |
| National Cyber Security Centre | UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations | 2026-07-23 18:36 | [Source Link](https://news.google.com/rss/articles/CBMiuwFBVV95cUxOYTBSeVlqSWkxQnlPVlJWQ3p3azJvT2F2eWZIVzd1T1BEbkV0cmJJaHNHbklZeEpMbFJIUUk5Ul9fM1FLVlI5V3hOdDhnMm8yNHlEOWF2cmlaTlVpVnI1Mi1xeElDRFZFZXE2b05MOEJkSFdWbS1WN3p6V2FTTEZjMWc5eGhDbHhHb0dkdWhjaG9QTDJhRm1DRVpYclR4cG5uU3BNVXBYRHpHRVNGdVFMUUhxYWpmcURfb2hJ?oc=5) |
| Reuters | US and allies say Russian hackers stole emails without social engineering | 2026-07-23 18:36 | [Source Link](https://news.google.com/rss/articles/CBMivwFBVV95cUxQVVJFNWJLRHJkZURIWFJhZXdEQmppOEhZMWVwWWZyQTFXcWRrOF8zTEFpZmR0dTV6ZEh3SVQ1bXA4blY1TWthQkNSRHZYR0MtRkI5UE5PZF96YnRTZ3JiTUt4VzZpbEsxRmVlZmZfSUZja1ktRW9lZXBOX2kwdjBoMjNpZWdXS2hBR29tX1NXREI5SHNQc1BDT3pYUzFJX05JQ2hxZWlsdlpPU0luSnhPb2hBTUQzU193TDhXVDc0Zw?oc=5) |
| CNN | New warnings that Russian operatives are targeting the emails of US nuclear scientists and defense contractors | 2026-07-23 18:36 | [Source Link](https://news.google.com/rss/articles/CBMif0FVX3lxTFBZTkFEV3ZJekNtUjh2WmpVd04yWlBnUXh5UWsteWNrN3kyb1RMTm9yWVdLZy14bFBuNS10UjM2V1gwN0hmSEhEU2Nta3h4cERtZDJSTHNMdUdwWFZJNXZNSGRsTzdaNnNEaFlldUI0amFhYXZYd3l0czVZMGdjQ0U?oc=5) |
| Proofpoint | TA488 Targets Zimbra Mailservers with Half-Click Exploits | 2026-07-23 18:36 | [Source Link](https://news.google.com/rss/articles/CBMipAFBVV95cUxNUjNRaGxsN0F0c3laMFp2cjdRQTNabVllOE5PVU53Yy1LVHZaa0trRDJ3blZnZzZZVDZ6ZWlPVGFxdFNKZFdkRkE0SVlhSGc4T3dCeGhhS1l0ak4zb0ZXRHVDUGZKNVpyRy1ZUXZqVHFINENVQTNELTZoZ2EzMVIwTU1vM2VydXY3TERHd3E5Y0ZsYmcyYW10bkZJX2FOSmpBaFpKTA?oc=5) |
| The Hacker News | Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes | 2026-07-23 18:36 | [Source Link](https://news.google.com/rss/articles/CBMifEFVX3lxTE5aY3dmWW93amd4VmFONVBRM0pnMTJ2dG9sa0xqM3U5Y3pQaDZCNWxVV1U2ZnIwT3Z1aU81OG1SaHNaQTdvbHd1aXJmSlhOdFowa1pDLUtKYjJGdHhqRi1XdVJ5anlocG5CcTZOVHRYek1oYkZyYzJzam1rWGo?oc=5) |

---
*Canonical Source: https://www.newsylist.com/trend/2026-07-24/russian-espionage-group-exploited-zimbra-zero-day-to-steal-mail-and-2fa-codes*
*Synthesized by Newsylist Open Intelligence Engine under E-E-A-T journalistic standards.*
