Russian APT targets Ukraine via Zimbra XSS flaw CVE-2025-66376
ID: 438e58df-2034-5001-9995-c02c2b2d603f
STIX ID: report--438e58df-2034-5001-9995-c02c2b2d603f
Feed Name: Security Affairs
A Russia-linked APT (assessed as APT28) exploited a stored XSS in Zimbra Collaboration (CVE-2025-66376, CVSS 7.2) by embedding obfuscated JavaScript in HTML phishing emails to steal credentials, session tokens, 2FA, and up to 90 days of mailbox data from Ukrainian government and critical infrastructure targets (Operation GhostMail); the campaign used SOAP API abuse, DNS/HTTPS exfiltration, and observable C2 domains and prompted Synacor patches and a CISA Known Exploited Vulnerability listing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
