Zimbra Collaboration Suite Stored XSS via CSS @import Active Exploitation (CVE-2025-66376) — Operation GhostMail

Zimbra Collaboration Suite Stored XSS via CSS @import Active (TL-2026-0266), also tracked as Operation GhostMail, is a critical-severity software vulnerability scored CVSS 7.2, first published 2026-03-21 and last reviewed 2026-09-19. It is attributed to APT28 (Russia) with high confidence, affects Zimbra Zimbra Collaboration Suite, references 1 CVE (CVE-2025-66376), maps to 70 MITRE ATT&CK techniques (T1001, T1005, T1027), and is covered by 9 detection rules and 64 indicators of compromise.

Key facts for TL-2026-0266

Threat ID
TL-2026-0266
Also known as
Operation GhostMail
Severity
CRITICAL
CVSS
7.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-03-21
Last reviewed
2026-09-19
Attribution
APT28
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
government, critical-infrastructure, education, defense
Target regions
Eastern Europe, Ukraine
Detection rules
9
Indicators of compromise
64
Updates
2026-09-19 · 8 updates · revalidated 8× · latest source

Malware and tooling in Zimbra Collaboration Suite Stored XSS via CSS @import Active

Malware and tooling: SpyPress.ZIMBRA variant

A stored cross-site scripting vulnerability in Zimbra Collaboration Suite Classic UI (CVE-2025-66376) allows unauthenticated attackers to execute arbitrary JavaScript via malicious CSS @import directives in HTML emails. Added to CISA KEV on March 18, 2026, the flaw is actively exploited by APT28 in Operation GhostMail targeting Ukrainian government entities for credential theft, session hijacking, and 90-day email exfiltration.

How Zimbra Collaboration Suite Stored XSS via CSS @import Active works

CVE-2025-66376 is a stored cross-site scripting (XSS) vulnerability in the Zimbra Collaboration Suite (ZCS) Classic UI caused by inadequate sanitization of CSS @import directives within HTML email content. The vulnerability affects ZCS versions 10.0.0 through 10.0.17 and 10.1.0 through 10.1.12, and was patched in versions 10.0.18 and 10.1.13 released on November 6, 2025.

The exploit mechanism leverages malicious CSS @import tokens embedded in HTML email bodies to bypass Zimbra's existing input filtering. When a victim opens the crafted email in the Zimbra Classic Web Client, the browser processes the @import directives, which can fetch external stylesheets or execute embedded JavaScript payloads. This creates a zero-click exploitation scenario — no user interaction is required beyond viewing the email in the webmail interface.

Seqrite Labs identified an active exploitation campaign dubbed Operation GhostMail, attributed to APT28 (Fancy Bear/UAC-0001) with medium confidence. The campaign targeted Ukraine's State Hydrology Agency (critical infrastructure) beginning January 22, 2026, using a compromised student email account from the National Academy of Internal Affairs (NAVS) as the delivery mechanism. The phishing email was crafted as a legitimate-looking internship inquiry.

The attack payload is a multi-stage JavaScript stealer hidden in a display:none div element, obfuscated with Base64 and XOR encoding (key: twichcba5e). Upon execution, the payload performs parallel data harvesting via Zimbra SOAP API calls including: identity scraping (GetIdentitiesRequest), server configuration dumping (GetInfoRequest), backup 2FA code theft (GetScratchCodesRequest), application-specific password creation (CreateAppSpecificPasswordRequest with name ZimbraWeb), mobile device enumeration (GetDeviceStatusRequest), OAuth consumer listing (GetOAuthConsumersRequest), browser password manager injection via autocomplete DOM manipulation, IMAP protocol enablement (ModifyPrefsRequest), and export of 90 days of email archives via the /home/~/?fmt=tgz endpoint.

Exfiltration occurs over dual channels: HTTPS POST requests to /v/p (structured data beacons) and /v/d (binary uploads), and DNS tunneling using Base32-encoded data in subdomain queries to the C2 infrastructure at zimbrasoft.com.ua. The C2 domains follow a pattern of js-[a-z0-9]{12}.i.zimbrasoft.com.ua, registered on January 20, 2026.

Persistence is achieved through creation of an application-specific password that survives credential resets, and enabling IMAP for ongoing mailbox access. The stolen session tokens (ZMBAuthToken) remain valid for approximately 90 days, providing extended unauthorized access.

CISA added CVE-2025-66376 to its Known Exploited Vulnerabilities catalog on March 18, 2026, with a remediation deadline of April 1, 2026 for federal agencies under BOD 22-01. Organizations running vulnerable Zimbra versions should immediately update to 10.0.18 or 10.1.13, or transition users to the Modern UI which uses a distinct rendering architecture unaffected by this flaw.

MITRE ATT&CK techniques used in TL-2026-0266

Command and Control

T1001 Data Obfuscation; T1071.004 Application Layer Protocol: DNS; T1090.002 Proxy: External Proxy; T1132.001 Data Encoding: Standard Encoding; T1573.002 Encrypted Channel: Asymmetric Cryptography

Collection

T1005 Data from Local System; T1074.002 Data Staged: Remote Data Staging; T1113 Screen Capture; T1114.002 Email Collection: Remote Email Collection; T1119 Automated Collection; T1560 Archive Collected Data; T1560.001 Archive Collected Data: Archive via Utility

defense-evasion

T1027 Obfuscated Files or Information; T1564 Hide Artifacts

Defense Evasion

T1027.013 Obfuscated Files or Information: Encrypted/Encoded File; T1027.017 Obfuscated Files or Information: SVG Smuggling; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1684.001 Impersonation

exfiltration

T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol

Exfiltration

T1048.003 Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol

execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution

Execution

T1059.007 Command and Scripting Interpreter: JavaScript; T1204 User Execution

discovery

T1069 Permission Groups Discovery; T1082 System Information Discovery; T1087 Account Discovery; T1120 Peripheral Device Discovery

command-and-control

T1071 Application Layer Protocol; T1102 Web Service

Initial Access

T1078.004 Valid Accounts: Cloud Accounts; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566.001 Phishing: Spearphishing Attachment; T1566.002 Phishing: Spearphishing Link

Discovery

T1087.003 Account Discovery: Email Account; T1518 Software Discovery; T1526 Cloud Service Discovery

persistence

T1098 Account Manipulation

Persistence

T1098.001 Account Manipulation: Additional Cloud Credentials; T1556.006 Modify Authentication Process: Multi-Factor Authentication

Credential Access

T1110.003 Brute Force: Password Spraying; T1187 Forced Authentication; T1552 Unsecured Credentials; T1555.003 Credentials from Password Stores: Credentials from Web Browsers

credential-access

T1111 Multi-Factor Authentication Interception; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores; T1557 Adversary-in-the-Middle

collection

T1114 Email Collection; T1185 Browser Session Hijacking; T1213 Data from Information Repositories

initial-access

T1189 Drive-by Compromise; T1566 Phishing

lateral-movement

T1550 Use Alternate Authentication Material

defense-impairment

T1556 Modify Authentication Process

resource-development

T1583 Acquire Infrastructure; T1586 Compromise Accounts

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1583.003 Acquire Infrastructure: Virtual Private Server; T1584.003 Compromise Infrastructure: Virtual Private Server; T1584.004 Compromise Infrastructure: Server; T1586.002 Compromise Accounts: Email Accounts; T1587.001 Develop Capabilities: Malware; T1588.002 Obtain Capabilities: Tool

Reconnaissance

T1589 Gather Victim Identity Information

reconnaissance

T1598 Phishing for Information

Affected products and versions in Zimbra Collaboration Suite Stored XSS via CSS @import Active

  • Zimbra — Zimbra Collaboration Suite
    Vulnerable versions: 10.0.0 - 10.0.17; 10.1.0 - 10.1.12
    Fixed in: 10.0.18; 10.1.13

Remediation for Zimbra Collaboration Suite Stored XSS via CSS @import Active

Patches

  • Zimbra Collaboration Suite 10.0.18 (released 2025-11-06)
  • Zimbra Collaboration Suite 10.1.13 (released 2025-11-06)

Immediate actions

  • Update Zimbra Collaboration Suite to version 10.0.18 or 10.1.13 immediately
  • Transition all users from Classic UI to Modern UI as interim mitigation
  • Block C2 domain zimbrasoft.com.ua and all subdomains at DNS and perimeter firewalls
  • Revoke all application-specific passwords and regenerate 2FA backup codes
  • Invalidate all active Zimbra session tokens (ZMBAuthToken) organization-wide
  • Search email logs for messages containing CSS @import directives in HTML bodies

Workarounds

  • Migrate users to Zimbra Modern UI which uses distinct rendering architecture unaffected by this vulnerability
  • Disable Classic UI access at the server level if Modern UI migration is feasible
  • Implement web application firewall rules to detect and block CSS @import injection attempts

Longer-term hardening

  • Deploy Content Security Policy (CSP) headers on Zimbra webmail to restrict inline script execution
  • Implement email gateway filtering to strip or quarantine emails with embedded CSS @import directives
  • Enable audit logging for Zimbra SOAP API calls especially CreateAppSpecificPasswordRequest and ModifyPrefsRequest
  • Deploy DNS monitoring for Base32-encoded subdomain query patterns indicating DNS exfiltration
  • Conduct threat hunt for IOCs associated with Operation GhostMail across email infrastructure

CVEs associated with Zimbra Collaboration Suite Stored XSS via CSS @import Active

CVE-2025-66376

Weaknesses (CWE) in Zimbra Collaboration Suite Stored XSS via CSS @import Active

CWE-79

Timeline of Zimbra Collaboration Suite Stored XSS via CSS @import Active

Showing the 20 most recent tracked events.

  • Actor adds a rotating 10-character XOR obfuscation layer on top of existing Base64 encoding in the ZimReaper payload to evade signature-based detection.
  • Laundry Bear (Void Blizzard) begins exploiting CVE-2025-66376 in Zimbra Classic UI as a zero-day, prior to any public patch.
  • Zimbra releases patched versions 10.0.18 and 10.1.13 fixing CVE-2025-66376 with dedicated CSS parsing that strips @import declarations, url() functions, and legacy expression() properties
  • Following the November 2025 silent patch, actors pivot to distributing phishing from compromised legitimate email accounts (including at isofts.kiev[.]ua and navs.edu[.]ua) to keep reaching unpatched or delayed-patch victims.
  • Zimbra Collaboration Suite 10.0 reaches end-of-life, receiving no further security updates and leaving unmigrated instances permanently exposed to CVE-2025-66376.
  • CVE-2025-66376 officially published in NVD with CVSS 7.2 HIGH rating and CWE-79 classification
  • APT28 registers C2 domain zimbrasoft.com.ua and establishes exfiltration infrastructure with subdomain pattern js-[a-z0-9]{12}.i.zimbrasoft.com.ua via ua.drs registrar
  • Operation GhostMail actors also attack a Ukrainian maritime-sector agency alongside the State Hydrology Agency, using compromised student-account phishing to deliver the CVE-2025-66376 payload.
  • APT28 launches Operation GhostMail spearphishing campaign against Ukraine State Hydrology Agency using compromised NAVS student email account as delivery mechanism
  • istc-cloud.com, the latest-identified TA488 C2 domain in the campaign, first observed active.
  • Proofpoint's last observed TA488 activity window closes around this date, with tracked campaign infrastructure reported dismantled — later contradicted by the 2026-07-23 report of continued Laundry Bear exploitation.
  • Seqrite Labs publishes comprehensive technical analysis of Operation GhostMail detailing APT28 exploitation of CVE-2025-66376 with full IOCs, attack chain, and MITRE mapping
  • CISA adds CVE-2025-66376 to Known Exploited Vulnerabilities catalog, mandating federal agency remediation by April 1, 2026 under BOD 22-01
  • CISA BOD 22-01 remediation deadline for federal agencies to patch or mitigate CVE-2025-66376
  • As of 2026-05-29, CVE-2025-66376 is patched (ZCS 10.0.18/10.1.13, Nov 2025) yet remains in CISA KEV and exploitable on unpatched Classic-UI Zimbra servers, with 10,000+ instances reportedly exposed. The Operation GhostMail campaign appears concluded, but actor APT28 stays fully active (PRISMEX, Storm-2754, account compromises through Apr-May 2026), so residual risk persists.
  • Zimbra Collaboration Suite 10.1.20 stands as the current supported release recommended for all upgrades.
  • Palo Alto Networks Unit 42 publishes detailed technical analysis of the campaign under tracking designation CL-STA-1114, including a fuller C2 IP/domain list (9 IPs, ~35.4-day domain rotation cycle).
  • CISA, jointly with U.K., European, Australian, and New Zealand agencies, publishes advisory AA26-204A formally attributing the CVE-2025-66376 exploitation campaign to Russian state-supported cyber actors.
  • BleepingComputer reports Laundry Bear (Void Blizzard) continues exploiting unpatched Zimbra servers for email theft, targeting Defense Industrial Base, government, energy, and NATO/Ukraine-priority sectors — contradicting the prior assessment that active exploitation had concluded.
  • Proofpoint discloses that TA488/LAUNDRY BEAR has pivoted the same half-click exploitation tradecraft to a new Microsoft Outlook Web Access XSS flaw (CVE-2026-42897) on on-premises Exchange Server, deploying the OWAReaper browser implant against government, telecom, financial, hospitality and aerospace targets.

Update history for TL-2026-0266

Sources cited for Zimbra Collaboration Suite Stored XSS via CSS @import Active

Threats related to Zimbra Collaboration Suite Stored XSS via CSS @import Active

Detection coverage for TL-2026-0266

As of 2026-09-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0266 across Splunk SPL, Microsoft KQL and Sigma, covering 64 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats