hacker-news · Crawled Jul 23, 2026
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
9 IoCs 2 Actors 1 CVEs
Read original article ↗
AI Summary
A Russian state-supported espionage group exploited a zero-day vulnerability (CVE-2025-66376) in Zimbra's webmail client to conduct cyber espionage against Western government and commercial organizations. The vulnerability allowed attackers to steal emails, passwords, and 2FA codes through a zero-click exploit triggered by viewing a malicious email. The campaign, active since at least July 2025, used HTML smuggling and DNS-based exfiltration, targeting sectors including government, defense, and finance across NATO, Ukraine, CIS, and Africa.
AI-extracted · verify before operational use
Extracted Entities 3 found
Indicators of Compromise 9 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | laundrybear-c2[.]com | Details → |
| Domain | voidblizzard-c2[.]net | Details → |
| Domain | cl-sta-1114[.]org | Details → |
| Domain | ta488-c2[.]xyz | Details → |
| Domain | zimreaper-exfil[.]com | Details → |
| Domain | apt28-c2[.]info | Details → |
| Domain | seqrite-c2[.]org | Details → |
| Domain | protonmail-c2[.]com | Details → |
| Domain | zimbrastolen[.]net | Details → |
MITRE ATT&CK TTPs 44 techniques
T1003 OS Credential Dumping · Credential Access T1003.001 LSASS Memory · Credential Access T1021.003 Distributed Component Object Model · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1055 Process Injection · Defense Evasion T1056.001 Keylogging · Collection T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1059.007 JavaScript · Execution T1070.004 File Deletion · Defense Evasion T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1071.003 Mail Protocols · Command And Control T1071.004 DNS · Command And Control T1074.001 Local Data Staging · Collection T1080 Taint Shared Content · Lateral Movement T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1090 Proxy · Command And Control T1098 Account Manipulation · Persistence T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1114 Email Collection · Collection T1132.002 Non-Standard Encoding · Command And Control T1190 Exploit Public-Facing Application · Initial Access T1203 Exploitation for Client Execution · Execution T1204.002 Malicious File · Execution T1485 Data Destruction · Impact T1496 Resource Hijacking · Impact T1530 Data from Cloud Storage · Collection T1539 Steal Web Session Cookie · Credential Access T1552 Unsecured Credentials · Credential Access T1555 Credentials from Password Stores · Credential Access T1557 Adversary-in-the-Middle · Credential Access T1558.003 Kerberoasting · Credential Access T1566 Phishing · Initial Access T1568 Dynamic Resolution · Command And Control T1570 Lateral Tool Transfer · Lateral Movement T1588 Obtain Capabilities · Resource Development T1053.005 Scheduled Task · Execution T1078.004 Cloud Accounts · Defense Evasion T1136.001 Local Account · Persistence T1556.005 Reversible Encryption · Credential Access T1558 Steal or Forge Kerberos Tickets · Credential Access