logo

Operation EmailThief: Active Exploitation of Zero-day XSS Vulnerability in Zimbra

ID: 4e9fe179-18fd-5bc9-ad59-f5315e1c87f3

STIX ID: report--4e9fe179-18fd-5bc9-ad59-f5315e1c87f3

Feed Name: Volexity Blog

Threat Score
80/100

Date Published: 2022-02-03

Date Updated: 2026-05-01

...
...

Volexity observed TEMP_HERETIC running targeted spear‑phishing campaigns in December 2021 that exploited a zero‑day XSS in Zimbra (affecting 8.8.15 builds) to load attacker JavaScript in authenticated webmail sessions and exfiltrate mailbox contents and attachments; the report includes IOCs (domains, IPs), infrastructure analysis (Freenom domains, BitLaunch hosts), mitigation recommendations, and attribution indicators pointing to a likely Chinese APT.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.