An email vulnerability let hackers steal data from governments around the world

Google's Threat Analysis Group revealed on Thursday that it discovered and worked to help patch an email server flaw used to steal data from governments in Greece, Moldova, Tunisia, Vietnam and Pakistan. The exploit, known as CVE-2023-37580, targeted email server Zimbra Collaboration to pilfer email data, user credentials and authentication tokens from organizations. 

It started in Greece at the end of June. Attackers that discovered the vulnerability and sent emails to a government organization containing the exploit. If someone clicked the link while logged into their Zimbra account, it automatically stole email data and set up auto-forwarding to take control of the address. 

While Zimbra published a hotfix on open source platform Github on July 5, most of the activity deploying the exploit happened afterward. That means targets didn't get around to updating the software with the fix until it was too late. It's a good reminder to update the devices you've been ignoring now, and ASAP as more updates become available. "These campaigns also highlight how attackers monitor open-source repositories to opportunistically exploit vulnerabilities where the fix is in the repository, but not yet released to users," the Google Threat Analysis Group wrote in a blog post. 

Around mid-July, it became clear that threat group Winter Vivern got ahold of the exploit. Winter Vivern targeted government organizations in Moldova and Tunisia. Then, a third unknown actor used the exploit to phish for credentials from members of the Vietnam government. That data got published to an official government domain, likely run by the attackers. The final campaign Google's Threat Analysis Group detailed targeted a government organization in Pakistan to steal Zimbra authentication tokens, a secure piece of information used to access locked or protected information.

Zimbra users were also the target of a mass-phishing campaign earlier this year. Starting in April, an unknown threat actor sends an email with a phishing link in an HTML file, according to ESET researchers. Before that, in 2022, threat actors used a different Zimbra exploit to steal emails from European government and media organizations.

As of 2022, Zimbra said it had more than 200,000 customers, including over 1,000 government organizations. "The popularity of Zimbra Collaboration among organizations expected to have lower IT budgets ensures that it stays an attractive target for adversaries," ESET researchers said about why attackers target Zimbra.

This article originally appeared on Engadget at https://www.engadget.com/an-email-vulnerability-let-hackers-steal-data-from-governments-around-the-world-160005510.html?src=rss https://www.engadget.com https://www.engadget.com/an-email-vulnerability-let-hackers-steal-data-from-governments-around-the-world-160005510.html?src=rss
Created 1y | Nov 16, 2023, 4:30:54 PM


Login to add comment

Other posts in this group

A bunch of robots ran a half-marathon alongside humans and it was incredibly goofy

Beijing held what’s being called the world’s first half-marathon for robots, allowing bipedal bots to compete alongside human runners, and as one might expect, ridiculousness ensued. The robots, wh

Apr 19, 2025, 11:10:18 PM | Engadget
Doctor Who ‘Lux’ review: Hope can change the world

Spoilers for “Lux.”

It’s an interesting time to be a long-running science fantasy media property in the streaming TV age. Star Trek is in the grip of an

Apr 19, 2025, 8:50:13 PM | Engadget
NASA’s Lucy spacecraft is about to have its second close encounter with an asteroid

A NASA spacecraft will make a close approach to an asteroid in the main belt on Sunday afternoon, in the second of several asteroid flybys planned for its 12-year mission to study remnants of the e

Apr 19, 2025, 6:30:12 PM | Engadget
Star Wars Zero Company looks like XCOM with Jedi and droids

EA and Lucasfilm shared first look at

Apr 19, 2025, 4:20:10 PM | Engadget
Real-time strategy game 'Tempest Rising' has been released early to all users

Tempest Rising, a real-time strategy game that's being called a "spiritual successor" a

Apr 19, 2025, 1:50:15 PM | Engadget
Here are the coolest cars at New York International Auto Show 2025

This year marks the 125th anniversary of the New York International Auto Show (NYIAS), and despite concerns over tariffs, there are still a lot of manufacturers here showing off new models includin

Apr 18, 2025, 9:40:18 PM | Engadget
Google is trying to get college students hooked on AI with a free year of Gemini Advanced

Under no circumstances should you let AI do your schoolwork for you, but Google has decided to make that option a little bit easier for the next year. The company is

Apr 18, 2025, 9:40:17 PM | Engadget