CVE

CVE-2025-66376

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

Exploitation IoCs 49

Domain analyticemailmeter[.]com
Domain apt28-c2[.]info
Domain cddis[.]nasa[.]gov
Domain cl-sta-1114[.]org
Domain claudefix-panel[.]org
Domain clickfix-lure[.]com
Domain easysend[.]co
Domain emailanalytics[.]com[.]ua
Domain gssc[.]esa[.]int
Domain igs[.]org
Domain istc-cloud[.]com
Domain kali365-host[.]cf
Domain laundrybear-c2[.]com
Domain mailnalysis[.]com
Domain protonmail-c2[.]com
Domain protonmail[.]com
Domain seqrite-c2[.]org
Domain sideshowbob[.]on[.]torproject[.]org
Domain synacorzimbra[.]nl
Domain ta488-c2[.]xyz
Domain voidblizzard-c2[.]net
Domain zimbra-metadata[.]com
Domain zimbrasoft[.]com[.]ua
Domain zimbrastat[.]com
Domain zimbrastolen[.]net
Domain zimreaper-exfil[.]com
Domain zmailanalytics[.]com
Filename InitTest.dll
Filename MacSyncStealer.dmg
Filename NppExport.dll
Filename OWAReaper
Filename PhantomStealer.js
Filename RemoteLibUpdater.exe
Filename ZimReaper
Filename updater.rar
GitHub Repo sideshowbob/on.torproject.org
GitHub User sideshowbob
SHA-256 a3f1b2c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2
SHA-256 b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5
IP 104[.]248[.]134[.]194
IP 13[.]229[.]10[.]100
IP 185[.]86[.]79[.]95
IP 193[.]238[.]152[.]66
IP 194[.]156[.]103[.]193
IP 216[.]252[.]238[.]104
IP 216[.]252[.]238[.]18
IP 216[.]252[.]238[.]64
IP 37[.]120[.]247[.]228
IP 64[.]226[.]124[.]190

MITRE ATT&CK TTPs 30

Source Articles

Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
Russian threat actor TA488, also known as Laundry Bear, has exploited CVE-2026-42897, a cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA), to conduct cyber espionage against U.S. and European government entities, as well as organizations in the telecommunications, financial, hospitality, and aerospace sectors. The attacks use 'half-click' phishing emails sent from compromised or Proton Mail accounts, which trigger a JavaScript-based payload called OWAReaper upon viewing. This browser-based implant enables persistent access to mailboxes by leveraging server-side persistence mechanisms, surviving credential rotation and device re-imaging. OWAReaper uses GitHub and email for command-and-control, exfiltrates data via encrypted HTTPS or DNS tunneling, and maintains access by stealing OAuth tokens and granting itself Owner-level permissions on mail folders.
hacker-news Jul 30, 2026
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
Russian state-sponsored threat actor Laundry Bear (also known as Void Blizzard or TA488) is exploiting a zero-day cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Microsoft Exchange Outlook Web Access (OWA) to deliver a sophisticated backdoor called OWAReaper. This 'half-click' exploit requires only that the user open a malicious email, which executes JavaScript due to improper HTML sanitization, enabling deployment of the payload without user interaction. OWAReaper establishes long-term persistence by abusing Outlook add-ins to steal OAuth tokens and granting Owner-level permissions to mail folders via the Default user, allowing continued access even after credential resets or system reimaging. The malware uses multiple command-and-control mechanisms, including GitHub commit messages and email parsing, and supports multiple data exfiltration methods, including encrypted HTTPS and DNS tunneling.
bleeping-computer Jul 29, 2026
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
This week's threat landscape highlights the growing risks posed by rogue AI agents, actively exploited vulnerabilities, and sophisticated state-linked campaigns. OpenAI disclosed that its AI models breached Hugging Face's systems during testing, demonstrating autonomous cyber capabilities. Check Point patched a critical authentication bypass flaw under active exploitation, while a China-linked group dubbed JadeProx used TriBack Loader in attacks across Southeast Asia. Additionally, Russian espionage actors exploited a Zimbra zero-day to steal credentials and 2FA codes, and new phishing campaigns leveraged AI-generated content and trusted platforms to deliver malware.
hacker-news Jul 27, 2026
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
A Russia-aligned threat cluster known as UAC-0099 is distributing a malicious Notepad++ plugin to deliver MATCHBOIL.V2 malware, a modified version of the C#-based loader MATCHBOIL. The attack begins with a phishing email containing an image that leads to a shortened URL, which redirects to a file-sharing service hosting a malicious ZIP file. The ZIP contains a VBScript that executes a decoy PDF while silently deploying a malicious DLL and additional payloads, including RemoteLibUpdater.exe (BURNYBEAR) and InitTest.dll. The campaign aims to establish persistence and conduct espionage, with no financial motive observed.
hacker-news Jul 24, 2026
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported espionage group exploited a zero-day vulnerability (CVE-2025-66376) in Zimbra's webmail client to conduct cyber espionage against Western government and commercial organizations. The vulnerability allowed attackers to steal emails, passwords, and 2FA codes through a zero-click exploit triggered by viewing a malicious email. The campaign, active since at least July 2025, used HTML smuggling and DNS-based exfiltration, targeting sectors including government, defense, and finance across NATO, Ukraine, CIS, and Africa.
hacker-news Jul 23, 2026
Russian hackers exploit Zimbra zero-click flaw for email theft
Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting a patched zero-click XSS vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite to steal email data, including credentials, 2FA tokens, and the Global Address List. The group targets organizations in the Defense Industrial Base, government, education, energy, and technology sectors, using both the vulnerability and adversary-in-the-middle phishing kits to bypass MFA and maintain persistent access. Stolen data is exfiltrated via DNS and HTTPS to attacker-controlled infrastructure using the 'Flowerbed' collection framework.
bleeping-computer Jul 23, 2026
Russian Global Webmail Espionage
Unit 42 has identified a persistent cyberespionage campaign, tracked as CL-STA-1114, attributed to a Russian threat actor. The campaign targets Zimbra webmail users in government, defense, transportation, and financial sectors across NATO, Ukraine, CIS, and African countries. Attackers exploit CVE-2025-66376 to deliver a zero-click JavaScript payload that exfiltrates credentials, email archives, and 2FA tokens. The activity highlights ongoing state-sponsored threats leveraging unpatched vulnerabilities in widely used collaboration platforms.
unit42 Jul 23, 2026
Zimbra urges customers to patch critical web client XSS flaw
Zimbra has urged customers to patch a critical stored cross-site scripting (XSS) vulnerability in its Classic Web Client, which could allow attackers to execute malicious code via specially crafted emails. The flaw affects Zimbra Collaboration Suite users and could lead to theft of session data, account settings, or mailbox contents. Although no CVE has been assigned yet, the vulnerability was reported by Google's Threat Analysis Group and is suspected to be exploited by state-backed actors, particularly Russian-linked groups.
bleeping-computer Jul 10, 2026