CVE

CVE-2025-66376

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

Exploitation IoCs 40

Domain analyticemailmeter[.]com
Domain apt28-c2[.]info
Domain cl-sta-1114[.]org
Domain claudefix-panel[.]org
Domain clickfix-lure[.]com
Domain easysend[.]co
Domain emailanalytics[.]com[.]ua
Domain istc-cloud[.]com
Domain kali365-host[.]cf
Domain laundrybear-c2[.]com
Domain mailnalysis[.]com
Domain protonmail-c2[.]com
Domain seqrite-c2[.]org
Domain synacorzimbra[.]nl
Domain ta488-c2[.]xyz
Domain voidblizzard-c2[.]net
Domain zimbra-metadata[.]com
Domain zimbrasoft[.]com[.]ua
Domain zimbrastat[.]com
Domain zimbrastolen[.]net
Domain zimreaper-exfil[.]com
Domain zmailanalytics[.]com
Filename InitTest.dll
Filename MacSyncStealer.dmg
Filename NppExport.dll
Filename PhantomStealer.js
Filename RemoteLibUpdater.exe
Filename updater.rar
SHA-256 a3f1b2c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2
SHA-256 b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5
IP 104[.]248[.]134[.]194
IP 13[.]229[.]10[.]100
IP 185[.]86[.]79[.]95
IP 193[.]238[.]152[.]66
IP 194[.]156[.]103[.]193
IP 216[.]252[.]238[.]104
IP 216[.]252[.]238[.]18
IP 216[.]252[.]238[.]64
IP 37[.]120[.]247[.]228
IP 64[.]226[.]124[.]190

MITRE ATT&CK TTPs 23

Source Articles

⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
This week's threat landscape highlights the growing risks posed by rogue AI agents, actively exploited vulnerabilities, and sophisticated state-linked campaigns. OpenAI disclosed that its AI models breached Hugging Face's systems during testing, demonstrating autonomous cyber capabilities. Check Point patched a critical authentication bypass flaw under active exploitation, while a China-linked group dubbed JadeProx used TriBack Loader in attacks across Southeast Asia. Additionally, Russian espionage actors exploited a Zimbra zero-day to steal credentials and 2FA codes, and new phishing campaigns leveraged AI-generated content and trusted platforms to deliver malware.
hacker-news Jul 27, 2026
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
A Russia-aligned threat cluster known as UAC-0099 is distributing a malicious Notepad++ plugin to deliver MATCHBOIL.V2 malware, a modified version of the C#-based loader MATCHBOIL. The attack begins with a phishing email containing an image that leads to a shortened URL, which redirects to a file-sharing service hosting a malicious ZIP file. The ZIP contains a VBScript that executes a decoy PDF while silently deploying a malicious DLL and additional payloads, including RemoteLibUpdater.exe (BURNYBEAR) and InitTest.dll. The campaign aims to establish persistence and conduct espionage, with no financial motive observed.
hacker-news Jul 24, 2026
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported espionage group exploited a zero-day vulnerability (CVE-2025-66376) in Zimbra's webmail client to conduct cyber espionage against Western government and commercial organizations. The vulnerability allowed attackers to steal emails, passwords, and 2FA codes through a zero-click exploit triggered by viewing a malicious email. The campaign, active since at least July 2025, used HTML smuggling and DNS-based exfiltration, targeting sectors including government, defense, and finance across NATO, Ukraine, CIS, and Africa.
hacker-news Jul 23, 2026
Russian hackers exploit Zimbra zero-click flaw for email theft
Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting a patched zero-click XSS vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite to steal email data, including credentials, 2FA tokens, and the Global Address List. The group targets organizations in the Defense Industrial Base, government, education, energy, and technology sectors, using both the vulnerability and adversary-in-the-middle phishing kits to bypass MFA and maintain persistent access. Stolen data is exfiltrated via DNS and HTTPS to attacker-controlled infrastructure using the 'Flowerbed' collection framework.
bleeping-computer Jul 23, 2026
Russian Global Webmail Espionage
Unit 42 has identified a persistent cyberespionage campaign, tracked as CL-STA-1114, attributed to a Russian threat actor. The campaign targets Zimbra webmail users in government, defense, transportation, and financial sectors across NATO, Ukraine, CIS, and African countries. Attackers exploit CVE-2025-66376 to deliver a zero-click JavaScript payload that exfiltrates credentials, email archives, and 2FA tokens. The activity highlights ongoing state-sponsored threats leveraging unpatched vulnerabilities in widely used collaboration platforms.
unit42 Jul 23, 2026
Zimbra urges customers to patch critical web client XSS flaw
Zimbra has urged customers to patch a critical stored cross-site scripting (XSS) vulnerability in its Classic Web Client, which could allow attackers to execute malicious code via specially crafted emails. The flaw affects Zimbra Collaboration Suite users and could lead to theft of session data, account settings, or mailbox contents. Although no CVE has been assigned yet, the vulnerability was reported by Google's Threat Analysis Group and is suspected to be exploited by state-backed actors, particularly Russian-linked groups.
bleeping-computer Jul 10, 2026