The Invisible Breach: ‘Operation GhostMail’ Uses Zero-Click XSS to Hijack Ukrainian Webmail
ID: ec0f3a4d-8fd8-5e2c-b50a-8bc7e0b6aa54
STIX ID: report--ec0f3a4d-8fd8-5e2c-b50a-8bc7e0b6aa54
Feed Name: securityonline.info
Threat Score
Operation GhostMail is a sophisticated, zero-click cyberespionage campaign exploiting a stored XSS vulnerability in Zimbra Collaboration (CVE-2025-66376) to run browser-resident JavaScript from an email’s HTML body, harvesting session tokens, 2FA codes, saved credentials, mailbox contents (90 days) and contacts, exfiltrating data over DNS and HTTPS, and attributed with moderate confidence to APT28 targeting Ukrainian critical infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
