Campaigns
Zimbra Collaboration Suite Zero Day Espionage Campaign

Zimbra Collaboration Suite Zero Day Espionage Campaign

ZimbraZero-DayCyber EspionageCredential TheftRussia
A Russian state-supported espionage group exploited a stored cross-site scripting zero-day, CVE-2025-66376, in Zimbra Collaboration Suite's Classic Web Client, allowing malicious JavaScript to execute inside a victim's authenticated webmail session the moment a crafted email was opened or previewed, with no click, attachment, or further interaction required. The payload, tracked by Proofpoint as ZimReaper and referenced by CISA as Ulej, stole CSRF tokens, autofilled passwords, and two-factor authentication scratch codes, exfiltrated up to 90 days of email and the full Global Address List, and created a persistent "ZimbraWeb" app-specific password for continued mailbox access without further

Indicators of Compromise

emailanalytics.com.ua
analyticemailmeter.com
mailnalysis.com
zimbra-metadata.com
zimbrasoft.com.ua
istc-cloud.com
synacorzimbra.nl
zimbrastat.com
zmailanalytics.com

APT Groups1

Void BlizzardRU
LAUNDRY BEARUAC-0190

Campaign Guidance

Remediation, mitigation, notes, history and related intelligence

Remediation/Detections

  • Upgrade all Zimbra Collaboration Suite 10.1 deployments to at least 10.1.13, and preferably the current 10.1.20 release; Zimbra 10.0 reached end of life on 31.12.2025 and 10.0.18 is an emergency floor only, not a supported destination.

  • Treat any mailbox that opened or previewed a matching message in a vulnerable Classic UI session as potentially compromised: reset the password, invalidate active sessions, and regenerate 2FA scratch codes.

  • Review /opt/zimbra/log/audit.log for CreateAppSpecificPassword calls and remove any credential named ZimbraWeb or similar.

  • Alert on SOAP calls to GetScratchCodesRequest, which should be rare in normal operation, and on accounts with zimbraPrefImapEnabled set to TRUE without a business need for IMAP.

  • Filter DNS traffic for the published C2 domains and alert on long, random subdomain lookups consistent with the DNS exfiltration schema (session ID, token-type key, Base32-encoded payload).

  • Pull unopened messages matching the fragmented @import / tag-splitting pattern using Proofpoint's published YARA rule (TA488_Zimbra_Exploit_Email).

Detection strategies validated against the MITRE ATT&CK Enterprise v19.1 STIX bundle (detects relationships):

Technique

Detection Strategy

Analytics

T1566.001

DET0236

AN0655, AN0656, AN0657

T1203

DET0287

AN0797, AN0798, AN0799

T1555.003

DET0037

AN0105, AN0106, AN0107

T1111

DET0246

AN0687, AN0688, AN0689

T1098

DET0096

AN0265–AN0270

T1087.003

DET0229

AN0641, AN0642

T1114.002

DET0048

AN0131, AN0132

T1071.004

DET0400

AN1121–AN1125

T1041

DET0348

AN0988–AN0991

Observed Countries2

UA (10)
US (156)