×
ItalianoEnglish
Set as default language

Grandangolo Communications

  • Home
  • Company
  • Services
    • Public Relation
    • Digital PR
    • Marketing
    • Lead Generation
    • Events
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages
  • Home
  • Customer Press Room
  • Eset
  • ESET: A massive campaign is underway to steal the credentials of users of Zimbra email services

Customer Press Room

ESET: A massive campaign is underway to steal the credentials of users of Zimbra email services

by Grandangolo Communications / Tuesday, 29 August 2023 / Published in Eset

The operation, which dates back to at least April 2023, is still ongoing. Targets include SMEs and government entities with the majority located in Poland; other European and Latin American countries were also affected

Researchers of ESET, a global European leader in the cybersecurity market, have uncovered a large-scale phishing campaign aimed at harvesting the credentials of users of Zimbra email accounts. The operation has been active since at least April 2023 and is still ongoing. Zimbra Collaboration is an open-core collaborative software platform, a popular alternative to enterprise email solutions. The campaign targets small and medium-sized businesses and government entities. According to ESET telemetry, the largest number of lenses is located in Poland; however, companies in other European countries including Ukraine, Italy, France and the Netherlands were also targeted. Latin American countries have also been affected, with Ecuador at the forefront.

While the operation is not particularly technically sophisticated, it is still capable of spreading and successfully compromising organizations using Zimbra Collaboration. “Hackers exploit the fact that HTML attachments contain legitimate code, with the only telltale element being a link pointing to the malicious host. In this way, it is much easier to circumvent reputation-related anti-spam policies, especially compared to more popular phishing techniques, in which a corrupted link is inserted directly into the body of the email,” explains Viktor Šperka, ESET researcher who discovered the countryside.

“The target organizations are of various types; the attackers do not focus on any specific vertical: the only aspect that connects the victims is the use of Zimbra,” adds Šperka. Zimbra Collaboration's popularity among organizations with smaller IT budgets makes it an attractive target for adversaries.

Initially, the victim receives an email with a phishing page in the attached HTML file. The message alerts you to an email server update, account deactivation, or similar issue and prompts you to click on the attached file. After opening the attachment, the user is presented with a fake Zimbra login page customized to the target organization. In the background, the submitted credentials are collected by the HTML form and sent to a server controlled by the attacker. Then, the attacker is potentially able to infiltrate the hacked email account. It is likely that the malicious operators managed to compromise the administrator accounts of the victims and created new email inboxes which were then used to send phishing emails to other targets. The campaign observed by ESET is based only on social engineering and user interaction; however, this may not be the only case.

Tagged under: Eset, Zimbra

About Grandangolo Communications

What you can read next

ESET announces version 6.0 of Mobile Security for Android
ESET Mobile Security for a safe return to class
ESET Research: Botnet Ebury is active and growing. 400 thousand violated Linux servers for cryptocurrency theft and profitless purpose

Customer Press Room

  • ESET Discover Promptlock, the first Ai-Powered ransomware

    Promptlock uses a model for ge ...
  • Acronis and Intel are alleged to provide a Threat Detection solution for Endpoints efficient and based on AI

    Acronis Cyber Protect Cloud sfrutta i processor...
  • Mimecast and Sentinelone redefine the management of Human-Centric computer risks thanks to an expansion of the partnership

    Sentinelone (NYSE: S) E MIMECAST Hanno recent ...
  • Vertiv completes the acquisition of Great Lakes Data Racks & Cabinets

    The acquisition strengthens the position of leaders ...
  • VERTIV Annaches ™ OneCore announces to accelerate the deployment of prefabricated scalable infrastructures for AI, HPC and high density data center from over 5 MW

    Global launch of an end-to-end solution that ...

Archives

  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018

Categories

  • A10
  • Abstract
  • abstract
  • Acronis
  • Ally Consulting
  • Arrow
  • Arrow Electronics
  • Axiante
  • Babel
  • Computer Center
  • Cohesity
  • Italy Cloud Consortium
  • Consys
  • D-Link
  • Eset
  • G.B. Service
  • Habble
  • HiSolution
  • HYCU
  • Icos
  • Information Tecnology
  • Ivanti
  • Link11
  • MobileIron
  • Netalia
  • Nethive
  • Nexthink
  • Nuvis
  • Praim
  • QAD
  • Qualys
  • Red Hot Cyber
  • Riverbed
  • Saviynt
  • Sensormatic
  • SentinelOne
  • Talent Software
  • Vectra
  • Vectra AI
  • Vertiv

Office printing, digital PR, marketing, lead generation: all projects are born from our passion and expertise, with an inevitable touch of creativity and innovation.

COMPANY

Grandangolo Communications Srl
Via Sardegna 19
20146 Milano
Telephone +39 335 8283393
info@grandangolo.it

I SERVIZI

  • Home
  • Company
  • Services
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages

CONTACTS

  • Contacts
  • Cookie policy
  • Privacy policy

© 2019 GRANDANGOLO COMMUNICATIONS SRL | P.IVA IT 06394850967 | All rights reserveD.

Powered by Webpowerplus

TOP