← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Operation GhostMail: Russian APT Exploits Zimbra XSS to Target Ukraine Government
A sophisticated phishing campaign targeting a Ukrainian government agency exploits a cross-site scripting vulnerability in Zimbra Collaboration Suite. The attack, attributed to a Russian APT group, uses a seemingly innocuous internship inquiry email to deliver a malicious JavaScript payload. When opened in a vulnerable Zimbra webmail session, the script silently executes, harvesting credentials, session tokens, 2FA codes, and mailbox contents. The multi-stage attack employs obfuscation techniques, SOAP API abuse, and dual-channel exfiltration via DNS and HTTPS. The campaign demonstrates the evolution of webmail-focused intrusions, relying on browser-resident stealers rather than traditional malware binaries.
MITRE ATT&CK & Malware Families
Indicators of Compromise (6)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| CVE | CVE-2025-66376 | — | 2026-03-17 | |
| FileHash-MD5 | c010f64080b0b0997b362a8e6b9c618e | — | 2026-03-17 | |
| domain | zimbrasoft.com.ua | — | 2026-03-17 | |
| hostname | i.zimbrasoft.com.ua | — | 2026-03-17 | |
| hostname | js-26tik3egye4.i.zimbrasoft.com.ua | — | 2026-03-17 | |
| hostname | js-l1wt597cimk.i.zimbrasoft.com.ua | — | 2026-03-17 |