SYMBOLCOMMON_NAMEaka. SYNONYMS
js.unidentified_007 (Back to overview)

Unidentified JS 007 (Zimbra Stealer)

Actor(s): APT28


According to Seqrite, this collector is delivered via a phishing mail and triggers via XSS in an active Zimbra session.

References
2026-03-17SeqriteSathwik Ram Prakki
Operation GhostMail: Russian APT exploits Zimbra Webmail to Target Ukraine State Agency
Unidentified JS 007 (Zimbra Stealer)

There is no Yara-Signature yet.