TF-MAL-js.unidentified_007
📛 Threat Title
Malware family: Unidentified JS 007 (Zimbra Stealer)
Description
ThreatFox malware family `js.unidentified_007`. Printable name: Unidentified JS 007 (Zimbra Stealer).
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cyberpress.org
CISA has issued an urgent alert regarding a newly discovered zero-day cross-site scripting (XSS) vulnerability in the Zimbra Collaboration Suite (ZCS) that is being actively exploited by threat actors. The flaw allows attackers to hijack user sessions, steal sensitive data, and manipulate email filters without requiring elevated privileges.
-
web:cybersecuritynews.com
A group of researchers recently published a significant mass-spreading phishing campaign targets Zimbra account users, shedding light on a campaign.
-
web:github.com
CVE-2022-41352 is an arbitrary file write vulnerability in Zimbra mail servers due to the use of a vulnerable cpio version. CVE-2022-41352 (NIST.gov) CVE-2022-41352 (Rapid7 Analysis) Affected Zimbra versions: Zimbra <9.0.0.p27 Zimbra <8.8.15.p34 (Refer to the patch notes for more details.) Remediation : In order to fix the vulnerability apply the latest patch (9.0.0.p27 and 8.8.15.p34 ...
-
web:malpedia.caad.fkie.fraunhofer.de
Unidentified JS 007 (Zimbra Stealer) Propose Change Actor (s): APT28 According to Seqrite, this collector is delivered via a phishing mail and triggers via XSS in an active Zimbra session.
-
web:wiki.zimbra.com
The following Security Vulnerabilities have been fixed and released in recent versions of Zimbra Collaboration software. For the latest release and patches, update Zimbra using your yum update or apt update.
-
web:www.cisa.gov
For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework.How to use the KEV ...
-
web:www.riskinsight-wavestone.com
How to identify an attacker's initial access after Zimbra compromission ? This article contain documentation to start your forensic analysis.
-
web:www.schneier.com
Weird Zimbra Vulnerability Hackers can execute commands on a remote computer by sending malformed emails to a Zimbra mail server. It's critical, but difficult to exploit reliably. In an email sent Wednesday afternoon, Proofpoint researcher Greg Lesnewich seemed to largely concur that the attacks weren't likely to lead to mass infections that could install ransomware or espionage malware ...
-
web:www.seqrite.com
Operation GhostMail uncovers a Russian APT campaign exploiting a Zimbra XSS vulnerability (CVE-2025-66376) to target a Ukrainian government agency via phishing emails and browser-based data exfiltration.
-
web:www.thaicert.or.th
388/68 Tuesday, October 7, 2025 Cybersecurity researchers from StrikeReady Labs have uncovered an in-the-wild attack exploiting a Zero-Day vulnerability in Zimbra Collaboration, tracked as CVE-2025-27915 (CVSS 5.4), targeting the Brazilian military through malicious ICS calendar files. Attackers impersonated the Office of Protocol of the Libyan Navy and sent emails with weaponized ICS ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.