{"id":3277,"date":"2026-09-30T17:57:56","date_gmt":"2026-09-30T17:57:56","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3277"},"modified":"2026-09-30T17:57:56","modified_gmt":"2026-09-30T17:57:56","slug":"attackers-exploit-zimbra-flaw-to-deploy-web-shells-and-harvest-authentication-secrets","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3277","title":{"rendered":"Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiNxFzgwNCn6YTNDvFIlEUKsnNOR9Y8UF__1rQ8N5BuMTKmJRPs-d_ilYcoeXwb03y07EXxnGyf5Ka8gyrKbFtzM2GoqYfrp79A-ZwHZyQDHEIU9twKFM67Glqk8eE4_j3fiHxNnPFl0euvHnKKfrmTd2aKcsMnebFQ4z73INLZfIdT66yH3MV5vOIBaMV5\/s1700-nu-rw-lo-l85-e365\/zimbra-email.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team.<\/p>\n<p>The attack exploits <strong>CVE-2026-73570<\/strong> (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol (SNMP) notifications are enabled and the optional zimbra-snmp package is installed.<\/p>\n<p>Exploitation of CVE-2026-73570 can be triggered by a specially crafted SMTP request (i.e., email against exposed Zimbra servers without requiring authentication or user interaction. The vulnerability was patched by Zimbra in July 2026 with the release of version 10.1.20.<\/p>\n<p>\u00abFollowing successful exploitation, observed activity included deployment of JSP web shells and reverse shells, privilege escalation, persistent remote-access tooling, and memory-backed execution,\u00bb the tech giant <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/09\/30\/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570\/\" target=\"_blank\">said<\/a>. \u00abThreat actors also accessed email and collected authentication and mailbox data, with archive creation and subsequent transfer activity observed.\u00bb<\/p>\n<p>Microsoft said it observed affected organizations in more than one region and industry, although not every host exhibited every stage of the attack chain. It&#8217;s currently not known who is behind the attacks.<\/p>\n<p>Details of active exploitation of CVE-2026-73570 were first highlighted by the Polish Computer Emergency Response Team (CERT Polska) in August 2026, with the agency urging users to review the \u00ab\/var\/log\/zimbra.log\u00bb file for suspicious Zimbra service restarts, and look for files created in temporary and Zimbra \u00abwebapps\u00bb directories.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Later that month, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) officially added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal agencies apply the fixes by August 24, 2026.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>Based on telemetry data, the attack activity documented by Microsoft was identified \u00abduring the interval\u00bb between July 20, 2026, when Zimbra version 10.1.20 was released, and August 13, 2026, when the flaw was publicly disclosed.<\/p>\n<p>Specifically, between July 28 and August 7, 2026, two distinct out-of-band scanning tools were found probing the injection path to validate command execution without delivering a follow-on payload.<\/p>\n<p>The attackers then abused this initial access pathway to run commands as the \u00abzimbra\u00bb service account and deploy multiple JSP web shells across Jetty and mailboxd application paths for redundancy, as well as download and execute malicious payloads directly through wget or curl, and establish interactive reverse shells.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhxMz7FTRxwz3cfRBXC5Tb0IMvbg595sK3TIyN4Fe4OfuvfN8wKsVqgy7VDc1pRXosp5UUTsn1SWIdNNVA8vUdA67g02XRs3_BEmAjCymicxdNEDU0AQxy9rL7HA8l8dUqa2k9g51mBpJwC3FecuaAfaQMo3WGT8wArqIWL_BaxkEqjVEiyKurA2CIJxrAS\/s1700-nu-rw-lo-l85-e365\/image-69.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhxMz7FTRxwz3cfRBXC5Tb0IMvbg595sK3TIyN4Fe4OfuvfN8wKsVqgy7VDc1pRXosp5UUTsn1SWIdNNVA8vUdA67g02XRs3_BEmAjCymicxdNEDU0AQxy9rL7HA8l8dUqa2k9g51mBpJwC3FecuaAfaQMo3WGT8wArqIWL_BaxkEqjVEiyKurA2CIJxrAS\/s1700-nu-rw-lo-l85-e365\/image-69.jpg\" alt=\"\" border=\"0\" data-original-height=\"650\" data-original-width=\"975\"\/><\/a><\/div>\n<p>\u00abOther execution chains used cron, systemd, or memfd_create to maintain recurring or memory-backed execution,\u00bb Microsoft said. \u00abIn some cases, attackers temporarily enabled write access to a public directory to deploy the web shell and then restored the directory permissions, limiting the visibility of the change during basic permission checks.\u00bb<\/p>\n<p>Some of the subsequent steps undertaken by the threat actor are listed below &#8211;<\/p>\n<ul>\n<li>Map the Zimbra deployment using zmprov to identify mailbox and MTA nodes for environment discovery.<\/li>\n<li>Check for the presence of the Zimbra SSH identity to likely facilitate movement between Zimbra hosts.<\/li>\n<li>Use a privilege-escalation technique that grants the \u00abzimbra\u00bb service account unrestricted and passwordless sudo access by modifying the \u00ab\/etc\/pam.d\/sudo\u00bb configuration file.<\/li>\n<li>Create a systemd service named \u00abzimlog.service\u00bb for a second persistence mechanism that establishes execution at system boot.<\/li>\n<li>Target Zimbra&#8217;s centralized service and authentication secrets by using the \u00abzmlocalconfig -s\u00bb command on the server rather than going after individual mailbox passwords. The recovered credentials are then used for authenticated LDAP queries to retrieve high-value attributes, such as zimbraPreAuthKey, zimbraAuthTokenKey, and zimbraTwoFactorAuthSecret.<\/li>\n<li>Utilize Zimbra&#8217;s existing SSH identity at \u00ab\/opt\/zimbra\/.ssh\/zimbra_identity\u00bb to enable lateral movement across other trusted nodes in the cluster. Rsync is used to transfer JSP web shells and other helper scripts between nodes.<\/li>\n<li>Employ an OpenSSL-encrypted reverse shell to attacker-controlled infrastructure to conduct command execution, payload retrieval, and exfiltration of command output.<\/li>\n<\/ul>\n<p>In at least one campaign, the attackers have been found to use a lightweight shell downloader for a Zimdown2 Go binary that then acts as an installer for the Zimclient2 remote-access agent. Zimclient2 offers interactive shell access, bidirectional file operations, and SOCKS5 proxying.<\/p>\n<p>\u00abIt supported WebSocket, TLS, and raw TCP transports, providing resilient remote access and potential network pivoting through compromised Zimbra servers,\u00bb Microsoft said. \u00abEvidence identified several persistence mechanisms associated with the payload, including systemd services, OpenRC, cron, shell startup files, SSH authorized keys, and local account creation.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/enterprise-ai-security-a\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhgJrVTpy3T5kJ7VEIro3XfMOmfqDnBU03fYT5CyFWrs2rE9BeQxs835FAS_f1yivzd7mZ7KartftPk4qs8w5Br-WzfYMXruXDQk4FiuXcvSxoA4XH93ipwJJyy2Hbs9jqs-keS9KZhCnQ2YYdv93M51kxJlE862ob-RrrEhP4DEVP3E79zMMPf43e5keoK\/s728-nu-rw-lo-l85-e365\/AI-eBook-d-2.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Also associated with the activity is the deployment of Zimbra-specific payloads. This includes a Go-based executable that attempts to extract Zimbra service-account credentials from \u00ab\/opt\/zimbra\/conf\/localconfig.xml,\u00bb and  use these values to construct MySQL and LDAP connection strings to the Zimbra MySQL instance and export the contents of the following database tables &#8211;<\/p>\n<ul>\n<li>mailbox<\/li>\n<li>mailbox_metadata<\/li>\n<li>mobile_devices<\/li>\n<li>out_of_office<\/li>\n<li>All tables in the zimbra.* namespace<\/li>\n<\/ul>\n<p>The implant also collects and stages credential, certificate, LDAP secret, mail-rule, and configuration artifacts. The harvested files are compressed into a ZIP archive for subsequent transfer to a remote endpoint.<\/p>\n<p>\u00abOn one compromised Zimbra server, the actor archived recent mailbox-backup content into \/opt\/zimbra\/final.tar.gz,\u00bb Microsoft said. \u00abThe actor then downloaded AzCopy from hxxps:\/\/aka[.]ms\/downloadazcopy-v10-linux and invoked it with an operator-supplied Azure Blob SAS URL targeting wsweb03[.]blob[.]core[.]windows[.]net\/log\/windows.log.\u00bb<\/p>\n<p>\u00abThis activity shows mailbox-data collection, local archive staging, and an exfiltration attempt using cloud-storage tooling; available evidence does not confirm that the transfer completed successfully.\u00bb<\/p>\n<p>To counter the threat, organizations are advised to apply the updates immediately. If patching is not an option, it&#8217;s recommended to uninstall the zimbra-snmp package, disable SNMP notifications, and restrict SNMP and SMTP access to trusted hosts only. Other safeguards include rotating Zimbra authentication secrets, scanning the server for redundant web shell persistence.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team.&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3278,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[622,396,229,120,70,142,145,214,213,750],"class_list":["post-3277","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-attackers","tag-authentication","tag-deploy","tag-exploit","tag-flaw","tag-harvest","tag-secrets","tag-shells","tag-web","tag-zimbra"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3277","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3277"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3277\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3278"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3277"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3277"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3277"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}