{"id":2054,"date":"2023-11-16T16:45:00","date_gmt":"2023-11-16T16:45:00","guid":{"rendered":"https:\/\/www.darkreading.com\/attacks-breaches\/apts-swarm-zimbra-zero-day-to-steal-government-info-worldwide"},"modified":"2023-11-16T16:45:00","modified_gmt":"2023-11-16T16:45:00","slug":"apts-swarm-zimbra-zero-day-to-steal-government-info-worldwide","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2023\/11\/16\/apts-swarm-zimbra-zero-day-to-steal-government-info-worldwide\/","title":{"rendered":"APTs Swarm Zimbra Zero-Day to Steal Government Info Worldwide"},"content":{"rendered":"<p><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/apts-swarm-zimbra-zero-day-to-steal-government-info-worldwide.jpg?w=640&#038;ssl=1\"><\/p>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/apts-swarm-zimbra-zero-day-to-steal-government-info-worldwide-1.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p>At least four separate cyberattack groups have used a former zero-day security vulnerability in the Zimbra Collaboration Suite (ZCS) to steal email data, user credentials, and authentication tokens from government organizations globally.<\/p>\n<p>ZCS is an email server, calendaring, and chat and video platform, used by &#8220;thousands&#8221; of companies and &#8220;hundreds of millions&#8221; of individuals, according to the Zimbra website. Its client organizations are as diverse as the Japan Advanced Institute of Science and Technology, Germany&#8217;s Max Planck Institute, and Gunung Sewu, a top business incubator in Southeast Asia.<\/p>\n<p>The bug <a href=\"https:\/\/www.darkreading.com\/endpoint\/zimbra-zero-day-demands-urgent-manual-update\" target=\"_blank\" rel=\"noopener\">(CVE-2023-37580) is a reflected cross-site scripting (XSS) vulnerability<\/a> in the Zimbra email server that was patched on July 25, with a hotfix rolling out to its public GitHub repository on July 5. According to a <a href=\"https:\/\/blog.google\/threat-analysis-group\/zimbra-0-day-used-to-target-international-government-organizations\/\" target=\"_blank\" rel=\"noopener\">report by Google&#8217;s Threat Analysis Group (TAG)<\/a> shared with Dark Reading, the zero-day exploitation started in June, before Zimbra offered remediation.<\/p>\n<h2 class=\"regular-text\">Four Separate Cyberattacks on World Governments<\/h2>\n<p>Google TAG has disclosed details on the government campaigns, which include:<\/p>\n<ul>\n<li>June 29: Unknown attackers target Greece.<\/li>\n<li>July 11: Winter Vivern APT campaign targets Moldova and Tunisia.<\/li>\n<li>July 20: Unknown attackers target Vietnam.<\/li>\n<li>Aug. 25: Unknown attackers target Pakistan.<\/li>\n<\/ul>\n<p>&#8220;The initial in-the-wild discovery of the zero-day vulnerability was a campaign targeting a government organization in Greece,&#8221; according to Google TAG researchers. &#8220;The attackers sent emails containing exploit URLs to their targets.&#8221;<\/p>\n<p>If a target clicked the link during a logged-in Zimbra session, the URL loaded a framework that steals users&#8217; emails and attachments; and, it set up an auto-forwarding rule to an attacker-controlled email address.<\/p>\n<p>The Winter Vivern campaign meanwhile went on for two weeks after beginning on July 11.<\/p>\n<p>&#8220;TAG identified multiple exploit URLs that targeted government organizations in Moldova and Tunisia; each URL contained a unique official email address for specific organizations in those governments,&#8221; according to the TAG analysis.<\/p>\n<p>The third zero-day campaign, by an unidentified group, was part of a phishing expedition against a government organization in Vietnam.<\/p>\n<p>&#8220;In this case, the exploit URL pointed to a script that displayed a phishing page for users&#8217; webmail credentials, and posted stolen credentials to a URL hosted on an official government domain that the attackers likely compromised,&#8221; Google researchers explained.<\/p>\n<p>The fourth campaign employed an N-day exploit to steal Zimbra authentication tokens from a government organization in Pakistan.<\/p>\n<p>&#8220;The discovery of at least four campaigns exploiting CVE-2023-37580 \u2026 demonstrates the importance of organizations applying fixes to their mail servers as soon as possible,&#8221; the advisory concluded. \u201cThese campaigns also highlight how attackers monitor open-source repositories to opportunistically exploit vulnerabilities where the fix is in the repository, but not yet released to users.&#8221;<\/p>\n<h2 class=\"regular-text\">Cyberattackers Target Juicy Mail Servers<\/h2>\n<p>There has been ongoing exploitation of vulnerabilities in mail servers, so organizations should prioritize patching them.<\/p>\n<p>Zimbra alone has been plagued by security incidents, including&nbsp;<a href=\"https:\/\/www.darkreading.com\/remote-workforce\/zimbra-rce-bug-under-active-attack\" target=\"_blank\" rel=\"noopener\">a remote code execution bug exploited as a zero-day in October 2022<\/a> and&nbsp;<a href=\"https:\/\/www.darkreading.com\/remote-workforce\/dprk-using-unpatched-zimbra-devices-to-spy-on-researchers-\" target=\"_blank\" rel=\"noopener\">an infostealing campaign by the nation of North Korea that preyed on unpatched servers<\/a>. And in January, CISA warned that threat actors <a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa22-228a\" target=\"_blank\" rel=\"noopener\">were exploiting multiple CVEs against ZCS<\/a>.<\/p>\n<p>Meanwhile, last month <a href=\"https:\/\/www.darkreading.com\/endpoint\/winter-vivern-blasts-webmail-0day-one-click-exploit\" target=\"_blank\" rel=\"noopener\">Winter Vivern was exploiting a zero-day flaw in Roundcube Webmail<\/a> servers, with a malicious email campaign targeting governmental organizations and a think tank in Europe that requires only that a user view a message.<\/p>\n<p>According to TAG: &#8220;The regular exploitation of XSS vulnerabilities in mail servers also shows a need for further code auditing of these applications, especially for XSS vulnerabilities.&#8221;<\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/apts-swarm-zimbra-zero-day-to-steal-government-info-worldwide\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>At least four separate cyberattack groups have used a former<\/p>\n","protected":false},"author":12,"featured_media":2055,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2054","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/apts-swarm-zimbra-zero-day-to-steal-government-info-worldwide.jpg?fit=310%2C310&ssl=1",310,310,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/apts-swarm-zimbra-zero-day-to-steal-government-info-worldwide.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/apts-swarm-zimbra-zero-day-to-steal-government-info-worldwide.jpg?fit=300%2C300&ssl=1",300,300,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/apts-swarm-zimbra-zero-day-to-steal-government-info-worldwide.jpg?fit=310%2C310&ssl=1",310,310,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/apts-swarm-zimbra-zero-day-to-steal-government-info-worldwide.jpg?fit=310%2C310&ssl=1",310,310,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/apts-swarm-zimbra-zero-day-to-steal-government-info-worldwide.jpg?fit=310%2C310&ssl=1",310,310,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/apts-swarm-zimbra-zero-day-to-steal-government-info-worldwide.jpg?fit=310%2C310&ssl=1",310,310,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/apts-swarm-zimbra-zero-day-to-steal-government-info-worldwide.jpg?fit=310%2C310&ssl=1",310,310,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/apts-swarm-zimbra-zero-day-to-steal-government-info-worldwide.jpg?resize=310%2C310&ssl=1",310,310,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/apts-swarm-zimbra-zero-day-to-steal-government-info-worldwide.jpg?resize=310%2C310&ssl=1",310,310,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/apts-swarm-zimbra-zero-day-to-steal-government-info-worldwide.jpg?fit=310%2C310&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2054","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2054"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2054\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2055"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2054"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2054"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2054"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}