logo

The Invisible Breach: ‘Operation GhostMail’ Uses Zero-Click XSS to Hijack Ukrainian Webmail

ID: ec0f3a4d-8fd8-5e2c-b50a-8bc7e0b6aa54

STIX ID: report--ec0f3a4d-8fd8-5e2c-b50a-8bc7e0b6aa54

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-03-20

Date Updated: 2026-04-23

Author: Ddos

...
...

Operation GhostMail is a sophisticated, zero-click cyberespionage campaign exploiting a stored XSS vulnerability in Zimbra Collaboration (CVE-2025-66376) to run browser-resident JavaScript from an email’s HTML body, harvesting session tokens, 2FA codes, saved credentials, mailbox contents (90 days) and contacts, exfiltrating data over DNS and HTTPS, and attributed with moderate confidence to APT28 targeting Ukrainian critical infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.