Russian APT Exploits Zimbra XSS to Target Ukrainian Government in ‘Operation GhostMail’
ID: 4b8285c8-4881-5b4d-a135-f1b4c734c0a0
STIX ID: report--4b8285c8-4881-5b4d-a135-f1b4c734c0a0
Feed Name: cybersecurityNews.com
Operation GhostMail: A Russian state-linked (attributed to APT28) targeted campaign abused a stored XSS in Zimbra Collaboration Suite (CVE-2025-66376) delivered via a benign-looking Ukrainian-language phishing email containing base64-encoded JavaScript. The two-stage, fileless browser loader and stealer exfiltrated session tokens, saved credentials, backup 2FA codes and up to 90 days of email archives to zimbrasoft.com.ua over HTTPS and DNS; the report provides IOCs and mitigation steps (upgrade Zimbra, revoke 'ZimbraWeb' app passwords, monitor SOAP API calls, disable unnecessary IMAP/POP3, and apply DNS filtering).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
