Skip to content
-
Subscribe to our newsletter & never miss our best posts. Subscribe Now!
  • https://www.facebook.com/
  • https://twitter.com/
  • https://t.me/
  • https://www.instagram.com/
  • https://youtube.com/
Excellentpix Excellentpix

Intelligence Redefined

Excellentpix Excellentpix

Intelligence Redefined

  • Green Energy
  • Tech News
  • Gadget
  • Smartphone
  • Laptop
  • PC
  • About Us
    • Advertise Here
    • Contact Us
    • Privacy Policy
    • Sitemap
  • Green Energy
  • Tech News
  • Gadget
  • Smartphone
  • Laptop
  • PC
  • About Us
    • Advertise Here
    • Contact Us
    • Privacy Policy
    • Sitemap
Subscribe
Close

Search

PC

Operation EmailThief: Zero-day XSS vulnerability in Zimbra email platform revealed

By Maria H. Gray
February 4, 2022 3 Min Read
Comments Off on Operation EmailThief: Zero-day XSS vulnerability in Zimbra email platform revealed

Researchers have uncovered an active campaign exploiting a zero-day vulnerability in the Zimbra email platform. 

Zimbra is an email platform available under an open source license. According to the developer, the platform supports hundreds of millions of mailboxes located in 140 countries. 

On February 3, cybersecurity researchers from Volexity, Steven Adair and Thomas Lancaster, said the system is being exploited by a threat group tracked as TEMP_Heretic in a series of spear phishing email attacks. 

In a security advisory, Volexity said the campaign, dubbed “Operation EmailThief,” was first discovered in December 2021 and is likely the work of Chinese cybercriminals. 

According to the team, TEMP_Heretic is careful in its selection of potential victims. The threat actor will first perform reconnaissance and will use tracker-embedded emails to see if an address was valid and if a target would even open emails in the first place — and if so, the second stage of the attack chain triggers. 

In total, 74 unique Microsoft Outlook email addresses have been used to send the preliminary emails, which contain generic images and subjects including invitations, alerts, and airline ticket refunds. 

TEMP_Heretic will then send tailored phishing emails containing a malicious link. The more targeted themes of subsequent emails related to interview requests from news organizations, including the AFP and BBC, as well as invitations to charity dinners. Other phishing email samples collected were more generic and contained holiday greetings. 

screenshot-2022-02-04-at-11-23-44.png

Volexity

The victim would need to be logged into the Zimbra webmail client from a web browser when they opened the malicious attachment & link for the exploit to be successful — but according to Volexity, the link itself could be launched from other apps, such as Outlook or Thunderbird. 

screenshot-2022-02-04-at-11-35-45.png

Volexity

The cross-site scripting (XSS) vulnerability allows attackers to run arbitrary JavaScript in the context of the Zimbra session, leading to the theft of mail data, attachments, and cookies. In addition, cybercriminals could leverage a compromised email account to send further phishing emails or to launch prompts for the victim to download additional malware payloads. 

TEMP_HERETIC has previously been linked to campaigns targeting European government and media organizations. 

“At the time of writing, this exploit has no available patch, nor has it been assigned a CVE (i.e., this is a zero-day vulnerability),” the researchers say. “Volexity can confirm and has tested that the most recent versions of Zimbra — 8.8.15 P29 & P30 — remain vulnerable; testing of version 9.0.0 indicates it is likely unaffected.”

Volexity notified Zimbra of the exploit attempt on December 16 and provided proof-of-concept (PoC) code. Zimbra acknowledged the report on December 28 and confirmed to the cybersecurity team that the exploit was valid. 

After requesting details of a patch in January, but having received no response, Volexity then made its findings public this month. However, users who have upgraded to the latest version of the webmail client are unlikely to be at risk.

“Users of Zimbra should consider upgrading to version 9.0.0, as there is currently no secure version of 8.8.15,” the researchers say. 

ZDNet has reached out to Zimbra and we will update when we hear back. 

Previous and related coverage


Have a tip? Get in touch securely via WhatsApp | Signal at +447713 025 499, or over at Keybase: charlie0


Source News

Tags:

EmailEmailThiefOperationplatformrevealedvulnerabilityXSSZeroDayZimbra
Author

Maria H. Gray

Follow Me
Other Articles
Previous

The Best News out of Sundance? Horror Movies to Get Excited About

Next

Samsung Galaxy S22 leak reveals why it could be the best phone for video viewing

September 2026
M T W T F S S
 123456
78910111213
14151617181920
21222324252627
282930  
« Aug    

Archives

Categories

  • Car
  • Entertainment
  • Gadget
  • Games
  • general
  • Green Energy
  • internet marketing
  • Laptop
  • Lifestyle
  • PC
  • Property
  • Real estate
  • SEO
  • Smartphone
  • Start Up
  • Tech News
  • Technology

Recent Posts

  • Rev Your Engines: Unleashing the Future of Smart and Sustainable Cars
  • The Untold Growth Hacks of Unicorn Startups: How Tiny Companies Become Billion-Dollar Giants
  • The Future Unveiled: Latest Tech Breakthroughs You Can’t Miss
  • Top Laptops of 2024: Unleashing Power, Portability, and Performance
  • Boost Your PC’s Power: Creative Ways to Upgrade Your Computer Without Breaking the Bank

fiver

Fiverr Logo

Tags

Amazon Android announces app Apple Big Black Buy Car coming deals Electric Galaxy game games gaming Google Heres Hunter iPhone laptop Laptops launch Market Microsoft news phone Pro Release Review sale Sales Samsung Series Smartphone software startup startups Stock tech Tesla top Windows Xbox year

PHP 2026

thedomestikatedlife
radartcontest

BL

excellentpix.com

WhatsApp us