
Zimbra Collaboration Suite Zero Day Espionage Campaign
Indicators of Compromise
APT Groups1
Campaign Guidance
Remediation, mitigation, notes, history and related intelligence
Remediation/Detections
Upgrade all Zimbra Collaboration Suite 10.1 deployments to at least 10.1.13, and preferably the current 10.1.20 release; Zimbra 10.0 reached end of life on 31.12.2025 and 10.0.18 is an emergency floor only, not a supported destination.
Treat any mailbox that opened or previewed a matching message in a vulnerable Classic UI session as potentially compromised: reset the password, invalidate active sessions, and regenerate 2FA scratch codes.
Review /opt/zimbra/log/audit.log for CreateAppSpecificPassword calls and remove any credential named ZimbraWeb or similar.
Alert on SOAP calls to GetScratchCodesRequest, which should be rare in normal operation, and on accounts with zimbraPrefImapEnabled set to TRUE without a business need for IMAP.
Filter DNS traffic for the published C2 domains and alert on long, random subdomain lookups consistent with the DNS exfiltration schema (session ID, token-type key, Base32-encoded payload).
Pull unopened messages matching the fragmented @import / tag-splitting pattern using Proofpoint's published YARA rule (TA488_Zimbra_Exploit_Email).
Detection strategies validated against the MITRE ATT&CK Enterprise v19.1 STIX bundle (detects relationships):
Technique | Detection Strategy | Analytics |
DET0236 | AN0655, AN0656, AN0657 | |
DET0287 | AN0797, AN0798, AN0799 | |
DET0037 | AN0105, AN0106, AN0107 | |
DET0246 | AN0687, AN0688, AN0689 | |
DET0096 | AN0265–AN0270 | |
DET0229 | AN0641, AN0642 | |
DET0048 | AN0131, AN0132 | |
DET0400 | AN1121–AN1125 | |
DET0348 | AN0988–AN0991 |