logo

Russian APT targets Ukraine via Zimbra XSS flaw CVE-2025-66376

ID: 438e58df-2034-5001-9995-c02c2b2d603f

STIX ID: report--438e58df-2034-5001-9995-c02c2b2d603f

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-03-19

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

A Russia-linked APT (assessed as APT28) exploited a stored XSS in Zimbra Collaboration (CVE-2025-66376, CVSS 7.2) by embedding obfuscated JavaScript in HTML phishing emails to steal credentials, session tokens, 2FA, and up to 90 days of mailbox data from Ukrainian government and critical infrastructure targets (Operation GhostMail); the campaign used SOAP API abuse, DNS/HTTPS exfiltration, and observable C2 domains and prompted Synacor patches and a CISA Known Exploited Vulnerability listing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.