HomeSecurityWinter Vivern team exploits Zimbra flaw to steal email of...

Winter Vivern group exploits Zimbra flaw to steal NATO emails

Since February 2023, the Russian hacking group known as TA473 – or “Winter Vivern” – has been exploiting unpatched Zimbra endpoints to exfiltrate emails from NATO officials, government and military personnel, and diplomats.

See also: New AlienFox toolkit steals credentials for 18 cloud services

Winter Wyvern

Two weeks ago, Sentinel Labs uncovered a malicious operation by “Winter Vivern,” which included websites that mimicked European cybercrime agencies. The deceptive sites were designed to spread malware disguised as virus scanners.

In a recent report, Proofpoint revealed that malicious actors are exploiting the CVE-2022-27926 security vulnerability in Zimbra Collaboration servers to gain access to the confidential communications of NATO allies and their personnel.

See also: Mélofée: The latest malware targeting Linux servers

Targeting Zimbra

Winter Vivern malware actors launch their attacks using the Acunetix vulnerability scanner to detect any unpatched webmail platforms.

The hackers then distribute a phishing email from a compromised address that is disguised to look like someone familiar or associated with the target organization

Winter Vivern group exploits Zimbra flaw to steal NATO emails

The emails include a link that exploits the severity of CVE-2022-27926 in an exploited Zimbra infrastructure, allowing the injection of other JavaScript payloads into the website.

By exploiting the payloads, threat actors are able to extract usernames, passwords, and tokens from cookies originating from a compromised Zimbra endpoint. This allows them to gain unrestricted access to their targets' email accounts with ease.

Winter Vivern group exploits Zimbra flaw to steal NATO emails

This particular element shows the meticulousness of malicious actors in pre-attack identification, determining which gateway their victim is using before crafting phishing emails and creating a landing.

See also: QNAP: Warns of Linux Sudo vulnerability in NAS devices

The “Winter Vivern” malware not only used three levels of base64 to complicate analysis, but also pieces of legitimate JavaScript running alongside normal operations in a native webmail gateway. This made it nearly undetectable due to its seamless integration into the background.

Winter Wyvern

The attackers can then access confidential data in compromised webmails or even use them to monitor communication over a specified period. In addition, they can use these accounts for lateral phishing and spread their attack further to the targeted organizations.

Although researchers state that the "Winter Vivern" group is not particularly sophisticated, they follow an effective operational approach that works even against high-profile targets that fail to apply software patches quickly enough.

In this case, CVE-2022-27926 was fixed in Zimbra Collaboration 9.0.0 P24, released in April 2022.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS