Security News > 2023 > March > Winter Vivern hackers exploit Zimbra flaw to steal NATO emails

Winter Vivern hackers exploit Zimbra flaw to steal NATO emails
2023-03-30 21:56

A Russian hacking group tracked as TA473, aka 'Winter Vivern,' has been actively exploiting vulnerabilities in unpatched Zimbra endpoints since February 2023 to steal the emails of NATO officials, governments, military personnel, and diplomats.

Today, Proofpoint has published a new report on how the threat actor exploits CVE-2022-27926 on Zimbra Collaboration servers to access the communications of NATO-aligned organizations and persons.

Winter Vivern attacks begin with the threat actor scanning for unpatched webmail platforms using the Acunetix tool vulnerability scanner.

The emails contain a link that exploits the CVE-2022-27926 in the target's compromised Zimbra infrastructure to inject other JavaScript payloads into the webpage.

These payloads are then used to to steal usernames, passwords, and tokens from cookies received from the compromised Zimbra endpoint.

The hackers can use the breached accounts to carry out lateral phishing attacks and further their infiltration of the target organizations.


News URL

https://www.bleepingcomputer.com/news/security/winter-vivern-hackers-exploit-zimbra-flaw-to-steal-nato-emails/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2022-04-21 CVE-2022-27926 Unspecified vulnerability in Zimbra Collaboration 9.0.0
A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters.
network
low complexity
zimbra
6.1

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Zimbra 8 2 61 14 8 85