Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware ZimReaper

ZimReaper

TLP:CLEAR
Family

AI Analysis

No AI analysis yet.

Description

According to Proofpoint, ZimReaper is a JavaScript-based malware family delivered via a half-click cross-site scripting exploit (CVE-2025-66376) targeting Zimbra Collaboration Suite webmail servers, requiring only that the victim open or preview a malicious email in the webmail client. The exploit uses a tag-splitting technique where CSS "@import" directives fragment HTML tags to bypass Zimbra's client-side HTML sanitizer, allowing arbitrary JavaScript execution in the context of the authenticated webmail session. Once executed, ZimReaper steals the CSRF token, auto-filled credentials, and two-factor authentication codes from the browser, creates an app-specific password named "ZimbraWeb" for persistent IMAP/POP3/SMTP access, and exfiltrates stolen data via DNS queries and HTTP POST. The malware also enumerates the Global Address List and exfiltrates the last 90 days of the victim's emails in a TGZ archive, using obfuscation layers including XOR-encrypted payloads that evolved over the course of the campaign. Attributed to: Void Blizzard.

Details

Type
Unknown
Platforms
Windows
Linux
Macos
Confidence
80%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.