TA488, a Russia-aligned threat actor linked with medium confidence to Void Blizzard/Laundry Bear, exploited a zero-day flaw (CVE-2025-66376) in Zimbra's client-side HTML sanitizer using a tag-splitting technique with fake CSS @import directives to smuggle executable SVG/JavaScript payloads. The resulting malware, ZimReaper, requires only that a victim open/preview a crafted email in vulnerable Zimbra webmail to execute in the browser context, harvesting CSRF tokens, autofill credentials, and 2FA codes, establishing a persistent app-specific password bypassing MFA, and exfiltrating Global Address List data and up to 90 days of email via DNS tunneling and HTTP POST to Cloudflare-fronted C2 infrastructure. Targeting focused on Ukrainian government and US government/science/defense industrial base entities, with the campaign going dormant after public disclosure by Seqrite in early 2026.
DNS Exfiltration
2 posts
TA488 Targets Zimbra Mailservers with Half-Click Exploits Popular node-ipc npm Package Infected with Credential Stealer Recent versions of the popular npm package node-ipc (9.1.6, 9.2.3, 12.0.1) were compromised to include an obfuscated credential stealer. The malware executes upon CommonJS module load, harvests sensitive developer and cloud credentials, and exfiltrates the compressed data via DNS TXT queries to attacker-controlled infrastructure.