Home/News/Russian Group Exploited Zimbra Zero-Day for Mail and 2FA Theft
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Russian Group Exploited Zimbra Zero-Day for Mail and 2FA Theft

Russian Group Exploited Zimbra Zero-Day for Mail and 2FA Theft

A Russian state-sponsored espionage group successfully exploited a previously unknown vulnerability in Zimbra's webmail client for several months, gaining access to sensitive information within Western organizations. The exploitation allowed the attackers to exfiltrate the last 90 days of emails, the organization's complete email directory, stored browser passwords, and two-factor authentication recovery codes. The initial compromise was achieved simply by opening a specially crafted email, indicating a sophisticated phishing or watering hole attack vector.

This campaign, which began as early as June 2023, targeted entities across various sectors, including government, military, and critical infrastructure. The National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and international partner agencies issued a joint advisory on March 20, 2024, detailing the threat. The advisory highlighted that the attackers leveraged the "Zimbra Collaboration Suite" to achieve their objectives, referring to the vulnerability as CVE-2024-24705. The group, identified as "Ghostwriter" or "UNC1151," has a history of targeting government and military entities in NATO member states.

The attackers employed a multi-stage payload. The initial stage, triggered by opening the malicious email, downloaded a second-stage payload. This payload then proceeded to steal the aforementioned sensitive data. The advisory emphasized that the attackers were persistent, actively maintaining access and exfiltrating data over an extended period. The exploitation of this zero-day vulnerability underscores the ongoing threat posed by state-sponsored cyberespionage groups and the critical need for organizations to maintain robust security practices, including timely patching and advanced threat detection.

In response to the threat, agencies urged organizations using Zimbra to immediately apply available patches and review their security logs for any signs of compromise. The advisory also recommended implementing multi-factor authentication (MFA) for all user accounts and enhancing email security gateways to detect and block malicious content. The ongoing investigation by cybersecurity agencies aims to fully understand the scope of the compromise and to attribute the attacks definitively, while also working to prevent future exploitation of similar vulnerabilities.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next