Russian hackers TA488 utilized a "half-click" exploit to conduct a yearlong cyber espionage campaign targeting NATO allies and nuclear researchers.
Russian state-linked hackers, identified as TA488 (also known as Void Blizzard or Laundry Bear), conducted a yearlong cyber espionage campaign targeting US nuclear researchers, defense contractors, and government officials. The administration announced a joint cybersecurity advisory with over a dozen allied governments, noting that the operation aimed to collect sensitive intelligence on advanced nuclear research and defense technologies to support Russia’s military efforts against Ukraine. The hackers utilized a rare "half-click" exploit (CVE-2025-66376) in the Zimbra Collaboration Suite. This vulnerability allowed the group to compromise accounts simply when a victim opened a malicious email, requiring no clicks or downloads. Once successful, the hackers could steal three months of correspondence, contact directories, and two-factor authentication codes. The campaign demonstrated Moscow’s strategy of using Ukraine as a testing ground for new cyber techniques before deploying them against NATO members. While the group was highly active through early 2026, it reportedly vanished after researchers disclosed its infrastructure. One suspected member, a 30-year-old Russian national, was arrested by Thai authorities and extradited to the United States to face trial.
Sources
-
Russian Hackers Tried to Steal US and NATO Nuclear Fusion Research
UNITED24 Media
-
TA488 Targets Zimbra Mailservers with Half-Click Exploits
Proofpoint
-
New warnings that Russian operatives are targeting the emails of US nuclear scientists and defense contractors
CNN
-
This Russian cybercrime campaign can infect a user just by viewing an email
Yahoo