Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Did Trump say Iowans are ‘really troubled people’?

    October 1, 2026

    Brazilian government calls for probe into US funding of far-right causes | Elections News

    October 1, 2026

    Burnham’s reopening of Brexit debate is ‘biggest boost in my career’, says Farage | Nigel Farage

    October 1, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Did Trump say Iowans are ‘really troubled people’?
    • Brazilian government calls for probe into US funding of far-right causes | Elections News
    • Burnham’s reopening of Brexit debate is ‘biggest boost in my career’, says Farage | Nigel Farage
    • UK airlines to be banned from charging parents to sit with children | Airline industry
    • US deploys thousands of troops to Middle East as Donald Trump weighs strikes on Iran
    • Inside Microsoft’s big Copilot rethink
    • ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
    • Evernorth Wins Shareholder Vote for Nasdaq XRP Treasury Listing
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, October 1
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 30, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team.

    The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol (SNMP) notifications are enabled and the optional zimbra-snmp package is installed.

    Exploitation of CVE-2026-73570 can be triggered by a specially crafted SMTP request (i.e., email against exposed Zimbra servers without requiring authentication or user interaction. The vulnerability was patched by Zimbra in July 2026 with the release of version 10.1.20.

    “Following successful exploitation, observed activity included deployment of JSP web shells and reverse shells, privilege escalation, persistent remote-access tooling, and memory-backed execution,” the tech giant said. “Threat actors also accessed email and collected authentication and mailbox data, with archive creation and subsequent transfer activity observed.”

    Microsoft said it observed affected organizations in more than one region and industry, although not every host exhibited every stage of the attack chain. It’s currently not known who is behind the attacks.

    Details of active exploitation of CVE-2026-73570 were first highlighted by the Polish Computer Emergency Response Team (CERT Polska) in August 2026, with the agency urging users to review the “/var/log/zimbra.log” file for suspicious Zimbra service restarts, and look for files created in temporary and Zimbra “webapps” directories.

    Cybersecurity

    Later that month, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) officially added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal agencies apply the fixes by August 24, 2026.

    Based on telemetry data, the attack activity documented by Microsoft was identified “during the interval” between July 20, 2026, when Zimbra version 10.1.20 was released, and August 13, 2026, when the flaw was publicly disclosed.

    Specifically, between July 28 and August 7, 2026, two distinct out-of-band scanning tools were found probing the injection path to validate command execution without delivering a follow-on payload.

    The attackers then abused this initial access pathway to run commands as the “zimbra” service account and deploy multiple JSP web shells across Jetty and mailboxd application paths for redundancy, as well as download and execute malicious payloads directly through wget or curl, and establish interactive reverse shells.

    “Other execution chains used cron, systemd, or memfd_create to maintain recurring or memory-backed execution,” Microsoft said. “In some cases, attackers temporarily enabled write access to a public directory to deploy the web shell and then restored the directory permissions, limiting the visibility of the change during basic permission checks.”

    Some of the subsequent steps undertaken by the threat actor are listed below –

    • Map the Zimbra deployment using zmprov to identify mailbox and MTA nodes for environment discovery.
    • Check for the presence of the Zimbra SSH identity to likely facilitate movement between Zimbra hosts.
    • Use a privilege-escalation technique that grants the “zimbra” service account unrestricted and passwordless sudo access by modifying the “/etc/pam.d/sudo” configuration file.
    • Create a systemd service named “zimlog.service” for a second persistence mechanism that establishes execution at system boot.
    • Target Zimbra’s centralized service and authentication secrets by using the “zmlocalconfig -s” command on the server rather than going after individual mailbox passwords. The recovered credentials are then used for authenticated LDAP queries to retrieve high-value attributes, such as zimbraPreAuthKey, zimbraAuthTokenKey, and zimbraTwoFactorAuthSecret.
    • Utilize Zimbra’s existing SSH identity at “/opt/zimbra/.ssh/zimbra_identity” to enable lateral movement across other trusted nodes in the cluster. Rsync is used to transfer JSP web shells and other helper scripts between nodes.
    • Employ an OpenSSL-encrypted reverse shell to attacker-controlled infrastructure to conduct command execution, payload retrieval, and exfiltration of command output.

    In at least one campaign, the attackers have been found to use a lightweight shell downloader for a Zimdown2 Go binary that then acts as an installer for the Zimclient2 remote-access agent. Zimclient2 offers interactive shell access, bidirectional file operations, and SOCKS5 proxying.

    “It supported WebSocket, TLS, and raw TCP transports, providing resilient remote access and potential network pivoting through compromised Zimbra servers,” Microsoft said. “Evidence identified several persistence mechanisms associated with the payload, including systemd services, OpenRC, cron, shell startup files, SSH authorized keys, and local account creation.”

    Cybersecurity

    Also associated with the activity is the deployment of Zimbra-specific payloads. This includes a Go-based executable that attempts to extract Zimbra service-account credentials from “/opt/zimbra/conf/localconfig.xml,” and use these values to construct MySQL and LDAP connection strings to the Zimbra MySQL instance and export the contents of the following database tables –

    • mailbox
    • mailbox_metadata
    • mobile_devices
    • out_of_office
    • All tables in the zimbra.* namespace

    The implant also collects and stages credential, certificate, LDAP secret, mail-rule, and configuration artifacts. The harvested files are compressed into a ZIP archive for subsequent transfer to a remote endpoint.

    “On one compromised Zimbra server, the actor archived recent mailbox-backup content into /opt/zimbra/final.tar.gz,” Microsoft said. “The actor then downloaded AzCopy from hxxps://aka[.]ms/downloadazcopy-v10-linux and invoked it with an operator-supplied Azure Blob SAS URL targeting wsweb03[.]blob[.]core[.]windows[.]net/log/windows.log.”

    “This activity shows mailbox-data collection, local archive staging, and an exfiltration attempt using cloud-storage tooling; available evidence does not confirm that the transfer completed successfully.”

    To counter the threat, organizations are advised to apply the updates immediately. If patching is not an option, it’s recommended to uninstall the zimbra-snmp package, disable SNMP notifications, and restrict SNMP and SMTP access to trusted hosts only. Other safeguards include rotating Zimbra authentication secrets, scanning the server for redundant web shell persistence.

    Attackers Authentication Deploy exploit Flaw Harvest Secrets Shells Web Zimbra
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories

    Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says

    Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains

    Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

    Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks

    Why AI agents are like the dog that pushed kids into the Seine

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Did Trump say Iowans are ‘really troubled people’?

    October 1, 2026

    Brazilian government calls for probe into US funding of far-right causes | Elections News

    October 1, 2026

    Burnham’s reopening of Brexit debate is ‘biggest boost in my career’, says Farage | Nigel Farage

    October 1, 2026

    UK airlines to be banned from charging parents to sit with children | Airline industry

    October 1, 2026
    Latest Posts

    Max Miller Continues to Resist Pressure to Drop Out as Deadline Looms

    August 7, 2026

    Houthi attacks kill at least 10 in Yemen as rebels target oil-rich Marib

    August 8, 2026

    Scientists find unexpected life on Ötzi the Iceman’s 5,300-year-old body

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Did Trump say Iowans are ‘really troubled people’?

    October 1, 2026

    Brazilian government calls for probe into US funding of far-right causes | Elections News

    October 1, 2026

    Burnham’s reopening of Brexit debate is ‘biggest boost in my career’, says Farage | Nigel Farage

    October 1, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.