SYMBOLCOMMON_NAMEaka. SYNONYMS
js.zimreaper (Back to overview)

ZimReaper

Actor(s): Void Blizzard


According to Proofpoint, ZimReaper is a JavaScript-based malware family delivered via a half-click cross-site scripting exploit (CVE-2025-66376) targeting Zimbra Collaboration Suite webmail servers, requiring only that the victim open or preview a malicious email in the webmail client. The exploit uses a tag-splitting technique where CSS "@import" directives fragment HTML tags to bypass Zimbra's client-side HTML sanitizer, allowing arbitrary JavaScript execution in the context of the authenticated webmail session. Once executed, ZimReaper steals the CSRF token, auto-filled credentials, and two-factor authentication codes from the browser, creates an app-specific password named "ZimbraWeb" for persistent IMAP/POP3/SMTP access, and exfiltrates stolen data via DNS queries and HTTP POST. The malware also enumerates the Global Address List and exfiltrates the last 90 days of the victim's emails in a TGZ archive, using obfuscation layers including XOR-encrypted payloads that evolved over the course of the campaign.

References
2026-07-23ProofpointGreg Lesnewich, Konstantin Klinger, Mark Kelly, Nick Attfield, Saher Naumaan
TA488 Targets Zimbra Mailservers with Half-Click Exploits
ZimReaper
2026-07-23NSANSA
NSA and Partners Alert Zimbra Collaboration Suite Users of a Russian State-Supported Phishing Campaign
ZimReaper
2026-03-17SeqriteSathwik Ram Prakki
Operation GhostMail: Russian APT exploits Zimbra Webmail to Target Ukraine State Agency
ZimReaper

There is no Yara-Signature yet.