ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Zimbra Zero-Day Exploited to Target Brazilian Military via Malicious ICS Files

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-27915

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-27915
Stored XSS in Zimbra Collaboration Suite Classic Web Client via Malicious ICS Files

CVE-2025-27915 is a stored cross-site scripting (XSS) flaw in the Classic Web Client of Synacor Zimbra Collaboration Suite (ZCS) 9.0, 10.0, and 10.1, caused by insufficient sanitization of HTML content in ICS calendar files. It is triggered when a user views an email message containing a malicious ICS entry, at which point embedded JavaScript executes in the victim's session via an ontoggle event handler inside a tag. A successful attacker can run arbitrary JavaScript in the victim's session and perform unauthorized actions on the account, notably creating email filters that silently redirect messages to attacker-controlled addresses, enabling data exfiltration. Any organization running the affected ZCS versions whose users read mail through the Classic Web Client is exposed, since delivery of a single crafted email can compromise a session. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2025-10-07, and public reporting describes active zero-day attacks, including targeting of the Brazilian military via malicious ICS files.

Do: Upgrade affected ZCS 9.0, 10.0, and 10.1 deployments to the latest patched builds per Zimbra's security advisory and apply any vendor-recommended mitigations (federal agencies must act per CISA KEV/BOD 22-01 requirements). Hunt for suspicious ICS-based emails and calendar entries, and review user mail filter rules for unauthorized forwarding or redirection to attacker-controlled addresses. Consider restricting or disabling Classic Web Client access until systems are patched.

5.44% KEV PoC
  • Synacor Zimbra Collaboration Suite (ZCS) 9.0, 10.0, and 10.1 (Classic Web Client)
large≈30,000–50,000 internet-exposed Zimbra servers; total deployments including internal-only instances likely higher

Indicators of compromiseAll →

TypeIndicatorContext
domainffrk.netmails, contacts, and shared folders to an external server ("ffrk[.]net"). It also searches for emails in a specific folder, and
Full article498 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananOct 06, 2025Email Security / Zero-Day

A now patched security vulnerability in Zimbra Collaboration was exploited as a zero-day earlier this year in cyber attacks targeting the Brazilian military.

Tracked as CVE-2025-27915 (CVSS score: 5.4), the vulnerability is a stored cross-site scripting (XSS) vulnerability in the Classic Web Client that arises as a result of insufficient sanitization of HTML content in ICS calendar files, resulting in arbitrary code execution.

"When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript executes via an ontoggle event inside a <details> tag," according to a description of the flaw in the NIST National Vulnerability Database (NVD).

"This allows an attacker to run arbitrary JavaScript within the victim's session, potentially leading to unauthorized actions such as setting e-mail filters to redirect messages to an attacker-controlled address. As a result, an attacker can perform unauthorized actions on the victim's account, including e-mail redirection and data exfiltration."

The vulnerability was addressed by Zimbra as part of versions 9.0.0 Patch 44, 10.0.13, and 10.1.5 released on January 27, 2025. The advisory, however, makes no mention of it having been exploited in real-world attacks.

However, according to a report published by StrikeReady Labs on September 30, 2025, the observed in-the-wild activity involved unknown threat actors spoofing the Libyan Navy's Office of Protocol to target the Brazilian military using malicious ICS files that exploited the flaw.

The ICS file contained a JavaScript code that's designed to act as a comprehensive data stealer to siphon credentials, emails, contacts, and shared folders to an external server ("ffrk[.]net"). It also searches for emails in a specific folder, and adds malicious Zimbra email filter rules with the name "Correo" to forward the messages to [email protected].

As a way to avoid detection, the script is fashioned such that it hides certain user interface elements and detonates only if more than three days have passed since the last time it was executed.

It's currently not clear who is behind the attack, but earlier this year, ESET revealed that the Russian threat actor known as APT28 had exploited XSS vulnerabilities in various webmail solutions from Roundcube, Horde, MDaemon, and Zimbra to obtain unauthorized access.

A similar modus operandi has also been adopted by other hacking groups like Winter Vivern and UNC1151 (aka Ghostwriter) to facilitate credential theft.

Update

In a statement shared with The Hacker News, Zimbra said its investigation found no evidence of the flaw being exploited in attacks targeting Brazilian entities. "All ZCS instances running 9.0.0 Patch 44, 10.0.13, and 10.1.5 released in January 2025 or later are not affected, and pose no ongoing risk," it said.

The Hacker News has reached out to StrikeReady Labs for further comment, and we will update the story if we hear back.

(The story was updated after publication to include a response from Zimbra.)

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/10/zimbra-zero-day-exploited-to-target.html