Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
Overview
A Russian state-sponsored espionage group has exploited a previously unknown vulnerability in Zimbra's webmail client to gain unauthorized access to Western email accounts. This attack allowed the hackers to read the last 90 days of emails, access the entire email directory, and retrieve saved passwords and two-factor authentication recovery codes. The exploitation was triggered simply by opening a malicious email. The U.S. National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agency (CISA), along with their partners, have alerted organizations to this ongoing threat. This incident raises significant concerns about the security of email communications, especially for organizations using Zimbra, as it underscores the need for vigilance against such sophisticated attacks.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Zimbra webmail client
- Action Required: Organizations should apply any available patches for Zimbra, monitor email accounts for suspicious activity, and implement additional security measures such as enhanced two-factor authentication.
- Timeline: Newly disclosed
Original Article Summary
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening the message was enough to start it. The NSA, CISA and partner agencies published
Impact
Zimbra webmail client
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Organizations should apply any available patches for Zimbra, monitor email accounts for suspicious activity, and implement additional security measures such as enhanced two-factor authentication.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Zero-day, Vulnerability.