Drooid Logo
Back to story perspectives

Full Breakdown

Exploitation of Zimbra Zero-Day Vulnerability Targets Brazilian Military

10/6/2025, 7:59:30 PM

Overview of the Exploit

A zero-day vulnerability in the Zimbra Collaboration Suite, tracked as CVE-2025-27915, was exploited earlier in 2025 in targeted cyber attacks against the Brazilian military. This stored cross-site scripting (XSS) vulnerability, with a CVSS score of 5.4, arises from inadequate sanitization of HTML content in iCalendar (.ICS) files. When users open emails containing malicious ICS entries, embedded JavaScript executes, allowing attackers to hijack sessions, set email redirects, and exfiltrate sensitive data.

Attack Mechanism

The exploit was first identified by StrikeReady Labs, which reported that attackers spoofed the Libyan Navy's Office of Protocol to deliver malicious ICS files. These files contained a sophisticated JavaScript payload designed to steal credentials, emails, contacts, and shared folders, exfiltrating the data to an external server at "ffrk[.]net." The malicious script employs various evasion techniques, including delaying execution by 60 seconds, limiting activity to three days, and obscuring user interface elements to minimize detection.

Technical Details of the Vulnerability

The vulnerability specifically affects Zimbra versions 9.0.0 through 10.1.5. Attackers can exploit the flaw by embedding JavaScript within ICS files, which executes when the email is opened. This allows for unauthorized actions such as creating email filters to redirect messages to an attacker-controlled address, specifically a ProtonMail account labeled "Correo." The exploit's complexity suggests involvement from well-resourced actors, possibly state-sponsored groups.

Official Responses and Mitigation

Zimbra addressed the vulnerability with patches released on January 27, 2025, in versions 9.0.0 Patch 44, 10.0.13, and 10.1.5. However, evidence indicates that the exploit was actively used before these patches were made available. The incident highlights the critical importance of timely security updates in enterprise environments.

Criticism and Concerns

Experts have raised concerns regarding the implications of such vulnerabilities in enterprise systems. The use of a zero-day exploit for espionage against a military target underscores the potential for significant geopolitical ramifications. The tactics observed in this attack bear similarities to those employed by known threat groups, including UNC1151, a Belarusian cyber-espionage group.

Conclusion

The exploitation of CVE-2025-27915 serves as a stark reminder of the vulnerabilities present in widely used collaboration tools like Zimbra. As cyber threats continue to evolve, the necessity for robust security measures and prompt patching becomes increasingly critical to safeguard sensitive information against sophisticated attacks.