Select your language

WHAT ARE YOU LOOKING FOR?

Popular Tags

Raleigh, NC

32°F
Overcast Clouds Humidity: 53%
Wind: 0.45 M/S

Zimbra Servers Targeted in Attacks Delivering Web Shells and Harvesting Authentication Data

Zimbra Servers Targeted in Attacks Delivering Web Shells and Harvesting Authentication Data

Threat actors have been actively exploiting a recently patched vulnerability in Zimbra Collaboration Suite (ZCS) to gain unauthorized access to email environments, deploy web shells, and extract sensitive authentication data, according to new research from Microsoft's security team.

The attacks leverage CVE-2026-73570, a critical vulnerability with a CVSS score of 8.9. The flaw is an unauthenticated operating system command injection issue that can lead to remote code execution when Simple Network Management Protocol (SNMP) notifications are enabled and the optional zimbra-snmp package is installed. By sending specially crafted SMTP requests to internet-facing Zimbra servers, attackers can execute malicious commands without requiring user interaction or valid credentials. Zimbra addressed the vulnerability in version 10.1.20, released in July 2026.

Once the vulnerability is successfully exploited, attackers have been observed deploying JSP web shells, establishing reverse shell connections, escalating privileges, installing persistent remote-access tools, and executing malware directly in memory. Microsoft noted that compromised systems were also used to access email content and collect mailbox-related authentication data. Investigators observed attackers creating archives of harvested information before transferring them from victim environments.

The campaign has affected organizations across multiple industries and geographic regions, although attack patterns varied between victims. Microsoft has not yet attributed the activity to a specific threat group.

Evidence of real-world exploitation first emerged in August 2026 when Poland's CERT Polska warned organizations about suspicious activity targeting Zimbra servers. The agency advised administrators to inspect /var/log/zimbra.log for unexpected Zimbra service restarts and to review temporary directories and Zimbra web application folders for unauthorized files.

Later that month, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to remediate the issue by August 24, 2026.

Microsoft's telemetry indicates that attackers began targeting the flaw shortly after the release of the fix and before public disclosure. Between July 28 and August 7, researchers observed two separate scanning frameworks probing vulnerable servers to verify command execution capabilities, though these early probes did not deliver malicious payloads.

After confirming exploitation was possible, attackers executed commands through the compromised zimbra service account and established persistence by deploying several JSP web shells across multiple Jetty and mailboxd application directories. Malicious payloads were downloaded using tools such as wget and curl, while reverse shells provided interactive control over infected systems.

Additional persistence mechanisms included the abuse of cron jobs, systemd services, and memfd_create-based execution techniques that enabled malware to operate directly from memory. In some incidents, attackers temporarily modified directory permissions to upload web shells and later restored the original permissions, making detection more difficult during routine security reviews.

Key Post-Exploitation Activities

Following initial compromise, the attackers carried out numerous actions to strengthen their foothold and expand access:

  • Used zmprov to map the Zimbra infrastructure and identify mailbox and mail-transfer nodes.
  • Searched for Zimbra SSH identities to facilitate movement between trusted servers.
  • Modified /etc/pam.d/sudo to grant the zimbra service account passwordless and unrestricted sudo privileges.
  • Created a malicious systemd service named zimlog.service to maintain persistence after system reboots.
  • Extracted centralized Zimbra authentication secrets using zmlocalconfig -s, allowing them to obtain valuable LDAP attributes such as:
    • zimbraPreAuthKey
    • zimbraAuthTokenKey
    • zimbraTwoFactorAuthSecret
  • Leveraged the existing SSH identity located at /opt/zimbra/.ssh/zimbra_identity to move laterally across clustered Zimbra systems.
  • Used rsync to propagate web shells and supporting tools between servers.
  • Established encrypted reverse shell communications using OpenSSL to enable command execution, data theft, and payload delivery.

In one observed campaign, attackers deployed a lightweight downloader that installed a Go-based malware framework known as Zimclient2. The malware provided advanced remote-access capabilities, including interactive command execution, file transfers, SOCKS5 proxying, and support for WebSocket, TLS, and raw TCP communications. Investigators also identified multiple persistence techniques associated with the malware, including systemd services, OpenRC entries, cron tasks, SSH authorized keys, login startup scripts, and locally created user accounts.

Targeting Zimbra's Most Valuable Secrets

Researchers also observed the deployment of specialized Zimbra-focused malware designed to harvest service-account credentials from /opt/zimbra/conf/localconfig.xml. The tool used these credentials to build MySQL and LDAP connection strings, enabling direct access to sensitive Zimbra databases.

Among the targeted database content were:

  • mailbox
  • mailbox_metadata
  • mobile_devices
  • out_of_office
  • All tables within the zimbra.* database namespace

In addition to database theft, the malware collected credentials, certificates, LDAP secrets, mail routing rules, and various configuration artifacts. These files were packaged into ZIP archives for exfiltration.

Microsoft also documented an incident in which attackers collected mailbox backup data and archived it as /opt/zimbra/final.tar.gz. The threat actors then downloaded AzCopy and attempted to transfer the archive to a cloud storage container hosted on Microsoft Azure using a preconfigured Blob Storage SAS URL. While the activity demonstrates a clear effort to exfiltrate mailbox data, investigators were unable to confirm whether the transfer was completed successfully.

Mitigation Recommendations

Organizations running Zimbra servers should immediately apply the latest security updates. Where immediate patching is not feasible, defenders should:

  • Remove the zimbra-snmp package if it is not required.
  • Disable SNMP notifications.
  • Restrict SNMP and SMTP access to trusted systems only.
  • Rotate Zimbra authentication keys and secrets.
  • Audit servers for JSP web shells and unauthorized persistence mechanisms.
  • Review logs for suspicious service restarts or command execution activity.
  • Monitor for lateral movement involving Zimbra SSH identities.

The campaign highlights how rapidly threat actors can weaponize newly disclosed vulnerabilities, turning exposed collaboration and email servers into launching points for credential theft, mailbox surveillance, and long-term network compromise.

Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post. 

Cybersecurity Insight delivers timely updates on global cybersecurity developments, including recent system breaches, cyber-attacks, advancements in artificial intelligence (AI), and emerging technology innovations. Our goal is to keep viewers well-informed about the latest trends in technology and system security, and how these changes impact our lives and the broader ecosystem

Please fill the required field.