Search/horde
Known CVEs
0
Highest CVSS
In KEV
0
Vendor
ingo h3
Connections
38 relationships
Zimbra Zero-Day Exploited to Target Brazilian Military via Malicious ICS Files
A now patched security vulnerability in Zimbra Collaboration was exploited as a zero-day earlier this year in cyber attacks targeting the Brazilian military. Tracked as CVE-2025-27915 (CVSS score: 5.4), the vulnerability is a stored cross-site scripting (XSS) vulnerability in the Classic Web Client that arises as a result of insufficient sanitization of HTML content in ICS calendar files, resulting in arbitrary code execution. "When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript executes via an ontoggle event inside a tag," according to a description of the flaw in the NIST National Vulnerability Database (NVD). "This allows an attacker to run arbitrary JavaScript within the victim's session, potentially leading to unauthorized actions such as setting e-mail filters to redirect messages to an attacker-controlled address. As a result, an attacker can perform unauthorized actions on the victim's account, including e-mail redirection and data exfiltration." The vulnerability was addressed by Zimbra as part of versions 9.0.0 Patch 44, 10.0.13, and 10.1.5 released on January 27, 2025. The advisory, however, makes no mention of it having been exploited in real-world attacks. However, according to a report published by StrikeReady Labs on September 30, 2025, the observed in-the-wild activity involved unknown threat actors spoofing the Libyan Navy's Office of Protocol to target the Brazilian military using malicious ICS files that exploited the flaw. The ICS file contained a JavaScript code that's designed to act as a comprehensive data stealer to siphon credentials, emails, contacts, and shared folders to an external server ("ffrk[.]net"). It also searches for emails in a specific folder, and adds malicious Zimbra email filter rules with the name "Correo" to forward the messages to [email protected]. As a way to avoid detection, the script is fashioned such that it hides certain user interface elements and detonates only if more than three days have passed since the last time it was executed. It's currently not clear who is behind the attack, but earlier this year, ESET revealed that the Russian threat actor known as APT28 had exploited XSS vulnerabilities in various webmail solutions from Roundcube, Horde, MDaemon, and Zimbra to obtain unauthorized access. A similar modus operandi has also been adopted by other hacking groups like Winter Vivern and UNC1151 (aka Ghostwriter) to facilitate credential theft. Update In a statement shared with The Hacker News, Zimbra said its investigation found no evidence of the flaw being exploited in attacks targeting Brazilian entities. "All ZCS instances running 9.0.0 Patch 44, 10.0.13, and 10.1.5 released in January 2025 or later are not affected, and pose no ongoing risk," it said. The Hacker News has reached out to StrikeReady Labs for further comment, and we will update the story if we hear back. (The story was updated after publication to include a response from Zimbra.)
thehackernews.comOct 6, 2025extracted
North Korea’s Fake Recruiters Feed Stolen Data to IT Workers
The North Korean threat actor behind the DeceptiveDevelopment campaign is supplying stolen developer information to the country’s horde of fraudulent IT workers, ESET reports. Initially detailed in February but ongoing since at least 2023, the DeceptiveDevelopment campaign targets developers associated with cryptocurrency and decentralized finance projects with fake job offers aimed at information theft and malware infection. Similar to Operation Dream Job, Contagious Interview, and ClickFake Interview, DeceptiveDevelopment relies on fake announcements on popular platforms such as LinkedIn, Upwork, Freelancer.com, and others to lure developers. As part of these attacks, after the intended victim engages with the fake recruiter, they are invited to an interview during which they are tricked into executing malware on their systems. With most of these attacks targeting cryptocurrency developers, previous research suspected that the purpose of these attacks was financial gain, either through stealing the victim’s cryptocurrency assets or through infiltrating the organizations they were working for. According to ESET, these campaigns serve a secondary purpose as well: the fake recruiters harvest developer identities and hand them over to groups associated with fraudulent North Korean IT workers, which use the information to pose as job seekers and land remote work at unsuspecting companies. “To secure a real job position, they may employ several tactics, including proxy interviewing, using stolen identities, and fabricating synthetic identities with AI-driven tools,” ESET notes. Using social engineering and fake recruiter profiles, the threat actor behind DeceptiveDevelopment offers fake lucrative job opportunities, aimed at infecting victims’ systems with malware such as BeaverTail, InvisibleFerret, and OtterCookie. Last year, the attackers were seen using WeaselStore (an infostealer and backdoor also known as GolangGhost and FlexibleFerret), its Python variant PylangGhost, and TsunamiKit, a complex .NET spyware that also drops cryptocurrency miners. In April this year, the threat actor was seen deploying Tropidoor, which shares significant code with Lazarus’ PostNapTea RAT. In August, AkdoorTea, a variant of Akdoor, was seen. ESET’s investigation into DeceptiveDevelopment revealed a tight collaboration with North Korea’s network of fraudulent IT workers, which the cybersecurity firm tracks as WageMole. “Although these activities are conducted by two different groups, they are most likely connected and collaborating,” the cybersecurity firm notes in a research paper (PDF). Operating in teams, the IT workers focus on obtaining work in western countries, mainly in the US. In Europe, they target France, Poland, Ukraine, and Albania. “Each team has a dedicated ‘boss’ – a leader who oversees the team’s operation, sets quotas for the team members, and coordinates their work. The members have a number of responsibilities: acquiring work, completing work tasks, and self-education to improve their skillsets,” ESET notes. The North Korean IT workers, the cybersecurity firm says, do not focus solely on finding programming jobs. Some of them venture into civil engineering and architecture, impersonating real companies and engineers and producing engineering drawings with falsified approval stamps. “They also focus on self-education and report studying freely available online materials and tutorial sites, mostly focusing on web programming, blockchain, the English language and, in recent years, the integration of AI into various web applications,” ESET says. Related: US Sanctions Russian National, Chinese Firm Aiding North Korean IT Workers Related: RaccoonO365 Phishing Service Disrupted, Leader Identified Related: Applying the OODA Loop to Solve the Shadow AI Problem Related: Burn and Churn: CISOs and the Role of Cybersecurity Automation
securityweek.comSep 26, 2025extracted
ESET APT Activity Report Q4 2024–Q1 2025: Malware sharing, wipers and exploits
In the latest episode of the ESET Research Podcast, ESET Distinguished Researcher Aryeh Goretsky is joined by ESET Security Awareness Specialist Rene Holt to dissect the key findings from ESET’s APT Activity Report. The first actor that steps into the limelight is UnsolicitedBooker, a China-aligned APT group that has demonstrated a level of persistence that truly puts the "P" in APT. This group targeted the same organization three times over several years, attempting to deploy its signature backdoor, MarsSnake. This example highlights the relentless focus of certain groups that will stop at nothing to achieve their objectives. The conversation then shifts to the challenges of attribution, particularly with the increasing trend of tool-sharing, primarily among China-aligned actors such as Worok. Their tactic is to muddy the waters by using overlapping toolsets sourced from digital quartermasters, intertwining their activities with those of other groups such as LuckyMouse and TA428. Turning to Russia-aligned actors, the discussion focuses on groups like Sednit, Gamaredon, and Sandworm. Sednit’s latest activity revolves around Operation RoundPress, which originally targeted the popular webmail service Roundcube but has recently expanded to other platforms such as Horde, MDaemon, and Zimbra. Sednit has been using targeted emails, exploiting flaws in these services, and employing cross-site scripting to attack defense companies located in Bulgaria and Ukraine. Gamaredon remains one of the most active APTs in Ukraine, constantly tweaking its obfuscation techniques to stay ahead of detection. Meanwhile, Sandworm has intensified its use of data-wiping malware, deploying a new wiper called ZEROLOT multiple times in the past six months. This wiper operates with surgical precision, erasing specific files and directories without immediately taking down the entire system—an approach that ensures the malware can complete its destructive mission. Aryeh and Rene also delve into the activities of North Korea-aligned and Iran-aligned groups. If you’re interested in more details, be sure to listen to this episode of the ESET Research Podcast or download the latest ESET APT Activity Report. Discussed topics: UnsolicitedBooker (MarsSnake) 1:45 Worok (and its digital quartermasters) 4:50 Sednit (Operation RoundCube) 9:55 Gamaredon 13:55 Sandworm (ZEROLOT wiper) 16:15 DeceptiveDevelopment (WeaselStore, ClickFix) 24:10 MuddyWater vs Lyceum 29:40
welivesecurity.comJul 1, 2025extracted