ZimReaper is a browser-executed JavaScript information-stealing implant used against vulnerable Zimbra Collaboration Suite Classic UI webmail sessions. It has been associated with Russia-aligned espionage activity tracked as TA488, Void Blizzard, and Laundry Bear. The implant was delivered through crafted HTML phishing emails exploiting CVE-2025-66376; opening or previewing the message in a vulnerable authenticated Zimbra session was sufficient to execute the payload. ZimReaper steals CSRF tokens, browser-autofilled credentials, two-factor authentication recovery codes, Zimbra configuration details, address-directory data, and up to 90 days of mailbox content. It exfiltrates collected information through web requests and DNS-based channels. The implant also creates application-specific mailbox credentials to retain IMAP, POP3, and SMTP access without normal two-factor authentication, providing persistence after compromise. Observed targeting included Ukrainian government entities, U.S. government, nuclear, and defense-industrial organizations, as well as government, defense, transportation, financial, scientific, and education-sector entities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The campaign was found to have weaponized CVE-2025-66376, a stored cross-site scripting vulnerability in Zimbra's Classic UI, to deliver a malicious JavaScript payload dubbed ZimReaper to harvest email communications and other sensitive data.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The campaign was found to have weaponized CVE-2025-66376, a stored cross-site scripting vulnerability in Zimbra's Classic UI, to deliver a malicious JavaScript payload dubbed ZimReaper to harvest email communications and other sensitive data.
TA458 and Void Blizzard exploited the “Half-click” vulnerability in Zimbra, Outlook Web Access, Roundcube, and SOGo to use ZimReaper and OWAReaper to collect credentials, contacts, and emails, and establish long-term persistence.
...ultimately resulting in the deployment of a JavaScript payload dubbed ZimReaper that's capable of harvesting 90 days of the victim's mail and other valuable data.
...ultimately resulting in the deployment of a JavaScript payload dubbed ZimReaper that's capable of harvesting 90 days of the victim's mail and other valuable data.
Once the JavaScript payload, dubbed ZimReaper by Proofpoint, executes, it performs the following malicious actions: steals the CSRF token and the browser's autofilled password, retrieves 2FA scratch codes, creates an app-specific password named ZimbraWeb, brute-forces the Global Address List, and exfiltrates 90 days of the victim's mail.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
La technique dite half-click exploit ne nécessite que l’ouverture ou la prévisualisation de l’email pour déclencher l’exécution du code malveillant, sans aucune interaction supplémentaire.
MITRE ATT&CK Mapping Tactic Technique ID Technique Name Initial Access T1190 Exploit Public-Facing Application
MITRE ATT&CK Mapping Tactic Technique ID Technique Name Credential Access T1003 OS Credential Dumping (Browser Passwords)
Impact: Full account takeover — attackers steal session tokens, 2FA codes, browser-saved passwords, the entire Global Address List, and up to 90 days of mailbox data.
Ping du serveur C2 pour confirmer l’exploitation ... Exfiltration via requêtes DNS ... Exfiltration des 90 derniers jours d’emails via HTTP POST
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously targeted Zimbra; mentioned as the predecessor or evolutionary basis of OWAReaper. The content provides no further functional details.
A malicious JavaScript payload used in attacks against Zimbra to harvest email communications and other sensitive data.
Credential and email collection malware used to harvest credentials, contacts, and emails and maintain persistence in webmail environments.
Previously used by TA488 against Zimbra email servers to steal emails, passwords, application passcodes and two-factor authentication codes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.