s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-js.zimreaper

📛 Threat Title

Malware family: ZimReaper

Category: ZimReaper First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `js.zimreaper`. Printable name: ZimReaper.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (8)

  • web:malpedia.caad.fkie.fraunhofer.de

    According to Proofpoint, ZimReaper is a JavaScript-based malware family delivered via a half-click cross-site scripting exploit (CVE-2025-66376) targeting Zimbra Collaboration Suite webmail servers, requiring only that the victim open or preview a malicious email in the webmail client. The exploit uses a tag-splitting technique where CSS "@import" directives fragment HTML tags to bypass Zimbra ...

  • web:malpedia.caad.fkie.fraunhofer.de

    This page gives an overview of all malware families that are covered on Malpedia, supplemented with some basic information for each family .

  • web:www.abuseipdb.com

    62.169.31.126 was found in our database! This IP was reported 92 times. Confidence of Abuse is 0%: ?

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.microsoft.com

    GigaWiper, also tracked as BLUERABBIT, is a destructive backdoor that combines multiple wiping and ransomware-like capabilities into a single operational platform. This blog analyzes how the malware incorporates code from several previously separate malware families and provides guidance to help defenders detect and defend against similar threats.

  • web:www.microsoft.com

    ACR Stealer is an information-stealing malware family reportedly offered through a malware -as-a-service (MaaS) model and associated with the rebranding of Amatera Stealer. During this period, two campaigns stand out, together appearing frequently in reviewed recent intrusions.

  • web:www.ncsc.gov.uk

    How to defend organisations against malware or ransomware attacks.

  • web:www.sentinelone.com

    A vulnerability remediation program helps you identify, analyze, prioritize, and eliminate security weaknesses before cyber attackers could exploit them.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.