hacker-news · Crawled Oct 1, 2026

Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

6 IoCs 1 CVEs
Read original article ↗

AI Summary

Threat actors are exploiting a patched command injection vulnerability, CVE-2026-73570, in Zimbra Collaboration Suite (ZCS) to achieve remote code execution without authentication. The flaw is triggered via a crafted SMTP request when SNMP notifications are enabled and the zimbra-snmp package is installed. Upon exploitation, attackers deploy JSP web shells, establish reverse shells, escalate privileges, and harvest authentication secrets including LDAP credentials and service account data. They also perform lateral movement using Zimbra's SSH identity and exfiltrate mailbox data, sometimes using cloud tools like AzCopy targeting Azure Blob storage.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 6 extracted

Type Value Detail
Domain wsweb03[.]blob[.]core[.]windows[.]net Details →
Filename zimbra_identity Details →
Filename localconfig.xml Details →
Filename final.tar.gz Details →
Filename zimlog.service Details →
GitHub Repo aka.ms/downloadazcopy-v10-linux Details →

MITRE ATT&CK TTPs 12 techniques