Zimbra Collaboration Suite Stored XSS via CSS @import Active Exploitation (CVE-2025-66376) — Operation GhostMail
Zimbra Collaboration Suite Stored XSS via CSS @import Active (TL-2026-0266), also tracked as Operation GhostMail, is a critical-severity software vulnerability scored CVSS 7.2, first published 2026-03-21 and last reviewed 2026-09-19. It is attributed to APT28 (Russia) with high confidence, affects Zimbra Zimbra Collaboration Suite, references 1 CVE (CVE-2025-66376), maps to 70 MITRE ATT&CK techniques (T1001, T1005, T1027), and is covered by 9 detection rules and 64 indicators of compromise.
Key facts for TL-2026-0266
- Threat ID
- TL-2026-0266
- Also known as
- Operation GhostMail
- Severity
- CRITICAL
- CVSS
- 7.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-03-21
- Last reviewed
- 2026-09-19
- Attribution
- APT28
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- government, critical-infrastructure, education, defense
- Target regions
- Eastern Europe, Ukraine
- Detection rules
- 9
- Indicators of compromise
- 64
- Updates
- 2026-09-19 · 8 updates · revalidated 8× · latest source
Malware and tooling in Zimbra Collaboration Suite Stored XSS via CSS @import Active
Malware and tooling: SpyPress.ZIMBRA variant
A stored cross-site scripting vulnerability in Zimbra Collaboration Suite Classic UI (CVE-2025-66376) allows unauthenticated attackers to execute arbitrary JavaScript via malicious CSS @import directives in HTML emails. Added to CISA KEV on March 18, 2026, the flaw is actively exploited by APT28 in Operation GhostMail targeting Ukrainian government entities for credential theft, session hijacking, and 90-day email exfiltration.
How Zimbra Collaboration Suite Stored XSS via CSS @import Active works
CVE-2025-66376 is a stored cross-site scripting (XSS) vulnerability in the Zimbra Collaboration Suite (ZCS) Classic UI caused by inadequate sanitization of CSS @import directives within HTML email content. The vulnerability affects ZCS versions 10.0.0 through 10.0.17 and 10.1.0 through 10.1.12, and was patched in versions 10.0.18 and 10.1.13 released on November 6, 2025.
The exploit mechanism leverages malicious CSS @import tokens embedded in HTML email bodies to bypass Zimbra's existing input filtering. When a victim opens the crafted email in the Zimbra Classic Web Client, the browser processes the @import directives, which can fetch external stylesheets or execute embedded JavaScript payloads. This creates a zero-click exploitation scenario — no user interaction is required beyond viewing the email in the webmail interface.
Seqrite Labs identified an active exploitation campaign dubbed Operation GhostMail, attributed to APT28 (Fancy Bear/UAC-0001) with medium confidence. The campaign targeted Ukraine's State Hydrology Agency (critical infrastructure) beginning January 22, 2026, using a compromised student email account from the National Academy of Internal Affairs (NAVS) as the delivery mechanism. The phishing email was crafted as a legitimate-looking internship inquiry.
The attack payload is a multi-stage JavaScript stealer hidden in a display:none div element, obfuscated with Base64 and XOR encoding (key: twichcba5e). Upon execution, the payload performs parallel data harvesting via Zimbra SOAP API calls including: identity scraping (GetIdentitiesRequest), server configuration dumping (GetInfoRequest), backup 2FA code theft (GetScratchCodesRequest), application-specific password creation (CreateAppSpecificPasswordRequest with name ZimbraWeb), mobile device enumeration (GetDeviceStatusRequest), OAuth consumer listing (GetOAuthConsumersRequest), browser password manager injection via autocomplete DOM manipulation, IMAP protocol enablement (ModifyPrefsRequest), and export of 90 days of email archives via the /home/~/?fmt=tgz endpoint.
Exfiltration occurs over dual channels: HTTPS POST requests to /v/p (structured data beacons) and /v/d (binary uploads), and DNS tunneling using Base32-encoded data in subdomain queries to the C2 infrastructure at zimbrasoft.com.ua. The C2 domains follow a pattern of js-[a-z0-9]{12}.i.zimbrasoft.com.ua, registered on January 20, 2026.
Persistence is achieved through creation of an application-specific password that survives credential resets, and enabling IMAP for ongoing mailbox access. The stolen session tokens (ZMBAuthToken) remain valid for approximately 90 days, providing extended unauthorized access.
CISA added CVE-2025-66376 to its Known Exploited Vulnerabilities catalog on March 18, 2026, with a remediation deadline of April 1, 2026 for federal agencies under BOD 22-01. Organizations running vulnerable Zimbra versions should immediately update to 10.0.18 or 10.1.13, or transition users to the Modern UI which uses a distinct rendering architecture unaffected by this flaw.
MITRE ATT&CK techniques used in TL-2026-0266
Command and Control
T1001 Data Obfuscation; T1071.004 Application Layer Protocol: DNS; T1090.002 Proxy: External Proxy; T1132.001 Data Encoding: Standard Encoding; T1573.002 Encrypted Channel: Asymmetric Cryptography
Collection
T1005 Data from Local System; T1074.002 Data Staged: Remote Data Staging; T1113 Screen Capture; T1114.002 Email Collection: Remote Email Collection; T1119 Automated Collection; T1560 Archive Collected Data; T1560.001 Archive Collected Data: Archive via Utility
defense-evasion
T1027 Obfuscated Files or Information; T1564 Hide Artifacts
Defense Evasion
T1027.013 Obfuscated Files or Information: Encrypted/Encoded File; T1027.017 Obfuscated Files or Information: SVG Smuggling; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1684.001 Impersonation
exfiltration
T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol
Exfiltration
T1048.003 Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution
Execution
T1059.007 Command and Scripting Interpreter: JavaScript; T1204 User Execution
discovery
T1069 Permission Groups Discovery; T1082 System Information Discovery; T1087 Account Discovery; T1120 Peripheral Device Discovery
command-and-control
T1071 Application Layer Protocol; T1102 Web Service
Initial Access
T1078.004 Valid Accounts: Cloud Accounts; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566.001 Phishing: Spearphishing Attachment; T1566.002 Phishing: Spearphishing Link
Discovery
T1087.003 Account Discovery: Email Account; T1518 Software Discovery; T1526 Cloud Service Discovery
persistence
Persistence
T1098.001 Account Manipulation: Additional Cloud Credentials; T1556.006 Modify Authentication Process: Multi-Factor Authentication
Credential Access
T1110.003 Brute Force: Password Spraying; T1187 Forced Authentication; T1552 Unsecured Credentials; T1555.003 Credentials from Password Stores: Credentials from Web Browsers
credential-access
T1111 Multi-Factor Authentication Interception; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores; T1557 Adversary-in-the-Middle
collection
T1114 Email Collection; T1185 Browser Session Hijacking; T1213 Data from Information Repositories
initial-access
T1189 Drive-by Compromise; T1566 Phishing
lateral-movement
T1550 Use Alternate Authentication Material
defense-impairment
T1556 Modify Authentication Process
resource-development
T1583 Acquire Infrastructure; T1586 Compromise Accounts
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1583.003 Acquire Infrastructure: Virtual Private Server; T1584.003 Compromise Infrastructure: Virtual Private Server; T1584.004 Compromise Infrastructure: Server; T1586.002 Compromise Accounts: Email Accounts; T1587.001 Develop Capabilities: Malware; T1588.002 Obtain Capabilities: Tool
Reconnaissance
T1589 Gather Victim Identity Information
reconnaissance
Affected products and versions in Zimbra Collaboration Suite Stored XSS via CSS @import Active
- Zimbra — Zimbra Collaboration Suite
Vulnerable versions: 10.0.0 - 10.0.17; 10.1.0 - 10.1.12
Fixed in: 10.0.18; 10.1.13
Remediation for Zimbra Collaboration Suite Stored XSS via CSS @import Active
Patches
- Zimbra Collaboration Suite 10.0.18 (released 2025-11-06)
- Zimbra Collaboration Suite 10.1.13 (released 2025-11-06)
Immediate actions
- Update Zimbra Collaboration Suite to version 10.0.18 or 10.1.13 immediately
- Transition all users from Classic UI to Modern UI as interim mitigation
- Block C2 domain zimbrasoft.com.ua and all subdomains at DNS and perimeter firewalls
- Revoke all application-specific passwords and regenerate 2FA backup codes
- Invalidate all active Zimbra session tokens (ZMBAuthToken) organization-wide
- Search email logs for messages containing CSS @import directives in HTML bodies
Workarounds
- Migrate users to Zimbra Modern UI which uses distinct rendering architecture unaffected by this vulnerability
- Disable Classic UI access at the server level if Modern UI migration is feasible
- Implement web application firewall rules to detect and block CSS @import injection attempts
Longer-term hardening
- Deploy Content Security Policy (CSP) headers on Zimbra webmail to restrict inline script execution
- Implement email gateway filtering to strip or quarantine emails with embedded CSS @import directives
- Enable audit logging for Zimbra SOAP API calls especially CreateAppSpecificPasswordRequest and ModifyPrefsRequest
- Deploy DNS monitoring for Base32-encoded subdomain query patterns indicating DNS exfiltration
- Conduct threat hunt for IOCs associated with Operation GhostMail across email infrastructure
CVEs associated with Zimbra Collaboration Suite Stored XSS via CSS @import Active
Weaknesses (CWE) in Zimbra Collaboration Suite Stored XSS via CSS @import Active
CWE-79
Timeline of Zimbra Collaboration Suite Stored XSS via CSS @import Active
Showing the 20 most recent tracked events.
- Actor adds a rotating 10-character XOR obfuscation layer on top of existing Base64 encoding in the ZimReaper payload to evade signature-based detection.
- Laundry Bear (Void Blizzard) begins exploiting CVE-2025-66376 in Zimbra Classic UI as a zero-day, prior to any public patch.
- Zimbra releases patched versions 10.0.18 and 10.1.13 fixing CVE-2025-66376 with dedicated CSS parsing that strips @import declarations, url() functions, and legacy expression() properties
- Following the November 2025 silent patch, actors pivot to distributing phishing from compromised legitimate email accounts (including at isofts.kiev[.]ua and navs.edu[.]ua) to keep reaching unpatched or delayed-patch victims.
- Zimbra Collaboration Suite 10.0 reaches end-of-life, receiving no further security updates and leaving unmigrated instances permanently exposed to CVE-2025-66376.
- CVE-2025-66376 officially published in NVD with CVSS 7.2 HIGH rating and CWE-79 classification
- APT28 registers C2 domain zimbrasoft.com.ua and establishes exfiltration infrastructure with subdomain pattern js-[a-z0-9]{12}.i.zimbrasoft.com.ua via ua.drs registrar
- Operation GhostMail actors also attack a Ukrainian maritime-sector agency alongside the State Hydrology Agency, using compromised student-account phishing to deliver the CVE-2025-66376 payload.
- APT28 launches Operation GhostMail spearphishing campaign against Ukraine State Hydrology Agency using compromised NAVS student email account as delivery mechanism
- istc-cloud.com, the latest-identified TA488 C2 domain in the campaign, first observed active.
- Proofpoint's last observed TA488 activity window closes around this date, with tracked campaign infrastructure reported dismantled — later contradicted by the 2026-07-23 report of continued Laundry Bear exploitation.
- Seqrite Labs publishes comprehensive technical analysis of Operation GhostMail detailing APT28 exploitation of CVE-2025-66376 with full IOCs, attack chain, and MITRE mapping
- CISA adds CVE-2025-66376 to Known Exploited Vulnerabilities catalog, mandating federal agency remediation by April 1, 2026 under BOD 22-01
- CISA BOD 22-01 remediation deadline for federal agencies to patch or mitigate CVE-2025-66376
- As of 2026-05-29, CVE-2025-66376 is patched (ZCS 10.0.18/10.1.13, Nov 2025) yet remains in CISA KEV and exploitable on unpatched Classic-UI Zimbra servers, with 10,000+ instances reportedly exposed. The Operation GhostMail campaign appears concluded, but actor APT28 stays fully active (PRISMEX, Storm-2754, account compromises through Apr-May 2026), so residual risk persists.
- Zimbra Collaboration Suite 10.1.20 stands as the current supported release recommended for all upgrades.
- Palo Alto Networks Unit 42 publishes detailed technical analysis of the campaign under tracking designation CL-STA-1114, including a fuller C2 IP/domain list (9 IPs, ~35.4-day domain rotation cycle).
- CISA, jointly with U.K., European, Australian, and New Zealand agencies, publishes advisory AA26-204A formally attributing the CVE-2025-66376 exploitation campaign to Russian state-supported cyber actors.
- BleepingComputer reports Laundry Bear (Void Blizzard) continues exploiting unpatched Zimbra servers for email theft, targeting Defense Industrial Base, government, energy, and NATO/Ukraine-priority sectors — contradicting the prior assessment that active exploitation had concluded.
- Proofpoint discloses that TA488/LAUNDRY BEAR has pivoted the same half-click exploitation tradecraft to a new Microsoft Outlook Web Access XSS flaw (CVE-2026-42897) on on-premises Exchange Server, deploying the OWAReaper browser implant against government, telecom, financial, hospitality and aerospace targets.
Update history for TL-2026-0266
- 2026-09-19 — TA488/Laundry Bear Exploits Zimbra CVE-2025-66376 with Half-Click XSS to Deploy ZimReaper Against Government Mail Servers: What changed No field escalations — severity (CRITICAL), exploitability (ACTIVE), status (ACTIVE), and attribution confidence (HIGH) were already at their current values from prior revalidation rounds that ingested this same AA26-204A/Proof
- 2026-09-19 — LAUNDRY BEAR Zero-Click Zimbra Phishing Campaign Exploits CVE-2025-66376 ("Ulej"/Beehive): What changed No change to severity (CRITICAL), exploitability (ACTIVE), status (ACTIVE), or CVSS (7.2) — all already at their ceiling on this record. New indicators (3) 2 new compromised-mailbox domains used for post-patch phishing distribu
- 2026-07-31 — LAUNDRY BEAR (Void Blizzard/TA488/CL-STA-1114) Exploits Zimbra Zero-Day CVE-2025-66376 in Year-Long "Half-Click" Email Espionage Campaign: What changed No field-level escalation (severity/exploitability/status/attribution already CRITICAL/ACTIVE/HIGH). Substantively new: a documented payload evolution (rotating XOR key added Oct 2025) and disclosure that the same actor cluster
- 2026-07-24 — Laundry Bear (Void Blizzard/TA488) Exploits Zimbra Classic UI XSS Flaw CVE-2025-66376 via ZimReaper to Mass-Harvest Webmail: What changed No field escalations — severity (CRITICAL), exploitability (ACTIVE), status (ACTIVE), CVSS (7.2), and attribution confidence (HIGH) already match the prior revalidated state. This update adds technical depth to the already-trac
- 2026-07-23 — CVE-2025-66376: Russian Espionage Group (LAUNDRY BEAR/Void Blizzard/CL-STA-1114/TA488) Exploits Zimbra Zero-Click XSS to Steal Mail, Credentials and 2FA Codes via ZimReaper: What changed No escalation of severity/exploitability/status — both already CRITICAL-tier ACTIVE in the existing record; the newer report's own HIGH severity label is a downgrade relative to the existing CRITICAL assessment and is not appli
- 2026-07-23 — Laundry Bear (Void Blizzard) Exploits Zimbra Zero-Day CVE-2025-66376 in Espionage Campaign: What changed No severity/exploitability/status escalation. The new report itself rates severity HIGH and attribution confidence MEDIUM, both below the existing record's CRITICAL severity / HIGH attribution confidence, so those fields were l
- 2026-07-23 — Laundry Bear Exploits Zero-Click Zimbra Webmail Flaw (CVE-2025-66376) in Espionage Campaign: What changed Attribution confidence MEDIUM → HIGH after formal joint international government attribution (CISA AA26-204A, 2026-07-23) naming Russian state-supported actors; severity escalated HIGH → CRITICAL given the confirmed broader NAT
- 2026-07-23 — Russian State-Sponsored Group Laundry Bear (Void Blizzard) Exploits Zimbra Zero-Click XSS (CVE-2025-66376) for Email Theft: What changed Status PATCHED → ACTIVE: a second, previously unreported actor (Laundry Bear/Void Blizzard) exploited CVE-2025-66376 as a zero-day before the November 2025 patch and, per a 2026-07-23 report, continues exploiting unpatched Zimb
Sources cited for Zimbra Collaboration Suite Stored XSS via CSS @import Active
- CISA KEV Catalog - CVE-2025-66376
- Zimbra Security Advisories
- Operation GhostMail: Russian APT Exploits Zimbra Webmail to Target Ukraine State Agency
- Russian APT targets Ukraine via Zimbra XSS flaw CVE-2025-66376
- Russian hackers exploit Zimbra flaw in Ukrainian govt attacks
- CISA orders feds to patch Zimbra XSS flaw exploited in attacks
- Russian APT Exploits Zimbra Vulnerability Against Ukraine
- Operation GhostMail Analysis - SecPod Blog
- CVE-2025-66376 - Stored XSS in Zimbra ZCS Classic UI
- CISA Warns of Zimbra Collaboration Suite Vulnerability Exploited in Attacks
Threats related to Zimbra Collaboration Suite Stored XSS via CSS @import Active
- Russian TA488 (Void Blizzard / Laundry Bear) Exploits Exchange OWA Zero-Day (CVE-2026-42897) with OWAReaper Backdoor for Long-Term Mailbox Access
- Void Blizzard (LAUNDRY BEAR) Russian State-Sponsored Cloud-Espionage Actor — Russian National Denis Nikolayevich Obrezko Charged (June 2026)
- APT28 (Fancy Bear) BEARDSHELL Backdoor & COVENANT C2 Framework — Long-term Ukrainian Military Espionage Campaign (CVE-2026-21509)
Detection coverage for TL-2026-0266
As of 2026-09-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0266 across Splunk SPL, Microsoft KQL and Sigma, covering 64 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.