An email vulnerability let hackers steal data from governments around the world

Google's Threat Analysis Group revealed on Thursday that it discovered and worked to help patch an email server flaw used to steal data from governments in Greece, Moldova, Tunisia, Vietnam and Pakistan. The exploit, known as CVE-2023-37580, targeted email server Zimbra Collaboration to pilfer email data, user credentials and authentication tokens from organizations. 

It started in Greece at the end of June. Attackers that discovered the vulnerability and sent emails to a government organization containing the exploit. If someone clicked the link while logged into their Zimbra account, it automatically stole email data and set up auto-forwarding to take control of the address. 

While Zimbra published a hotfix on open source platform Github on July 5, most of the activity deploying the exploit happened afterward. That means targets didn't get around to updating the software with the fix until it was too late. It's a good reminder to update the devices you've been ignoring now, and ASAP as more updates become available. "These campaigns also highlight how attackers monitor open-source repositories to opportunistically exploit vulnerabilities where the fix is in the repository, but not yet released to users," the Google Threat Analysis Group wrote in a blog post. 

Around mid-July, it became clear that threat group Winter Vivern got ahold of the exploit. Winter Vivern targeted government organizations in Moldova and Tunisia. Then, a third unknown actor used the exploit to phish for credentials from members of the Vietnam government. That data got published to an official government domain, likely run by the attackers. The final campaign Google's Threat Analysis Group detailed targeted a government organization in Pakistan to steal Zimbra authentication tokens, a secure piece of information used to access locked or protected information.

Zimbra users were also the target of a mass-phishing campaign earlier this year. Starting in April, an unknown threat actor sends an email with a phishing link in an HTML file, according to ESET researchers. Before that, in 2022, threat actors used a different Zimbra exploit to steal emails from European government and media organizations.

As of 2022, Zimbra said it had more than 200,000 customers, including over 1,000 government organizations. "The popularity of Zimbra Collaboration among organizations expected to have lower IT budgets ensures that it stays an attractive target for adversaries," ESET researchers said about why attackers target Zimbra.

This article originally appeared on Engadget at https://www.engadget.com/an-email-vulnerability-let-hackers-steal-data-from-governments-around-the-world-160005510.html?src=rss https://www.engadget.com https://www.engadget.com/an-email-vulnerability-let-hackers-steal-data-from-governments-around-the-world-160005510.html?src=rss
созданный 1y | 16 нояб. 2023 г., 16:30:54


Войдите, чтобы добавить комментарий

Другие сообщения в этой группе

Here are the coolest cars at New York International Auto Show 2025

This year marks the 125th anniversary of the New York International Auto Show (NYIAS), and despite concerns over tariffs, there are still a lot of manufacturers here showing off new models includin

18 апр. 2025 г., 21:40:18 | Engadget
Google is trying to get college students hooked on AI with a free year of Gemini Advanced

Under no circumstances should you let AI do your schoolwork for you, but Google has decided to make that option a little bit easier for the next year. The company is

18 апр. 2025 г., 21:40:17 | Engadget
Blizzard explains hero bans ahead of their introduction in competitive Overwatch

Blizzard has finally shared

18 апр. 2025 г., 21:40:16 | Engadget
The Apple Sports app now lets users create and share game cards

The Apple Sports app just introduced a new feature called Game Card Sharing. This lets users generate digital game cards that carry information about a specific match. The cards can be generated fo

18 апр. 2025 г., 19:20:15 | Engadget
Celebrate the 35th anniversary of the Hubble Space Telescope with a gigantic tower of gas and dust

As part of their ongoing celebration of the Hubble Space Telescope's

18 апр. 2025 г., 19:20:14 | Engadget
The rhythm-infused adventure Unbeatable has a new demo for PC and PS5

In the latest evidence that indie games are often where you find the boldest creative choices, look no further than Unbeatable. The hand‑drawn rhythm adventure title — announced in 2020 an

18 апр. 2025 г., 19:20:12 | Engadget
The Kia EV4 makes its US debut at the 2025 New York Auto Show

Kia's first all-electric sedan, the 2026 EV4, is making its official debut in the US at the

18 апр. 2025 г., 17:10:15 | Engadget