How did a single Zimbra phishing email turn into mailbox theft? CISA says LAUNDRY BEAR used CVE-2025-66376 so that just viewing the message could execute JavaScript in the webmail client and start mail theft[1][2].
🧵 1/5
The initial payload was hidden in an SVG onload field, wrapped in Base64 and XOR layers, and relied on repeated @import directives plus 12 asynchronous stages to reach its logic[3].
🧵 2/5
From there, the script tried to identify the victim, steal saved passwords through browser autocomplete, enable IMAP, create an Application Passcode named ZimbraWeb, and collect 2FA scratch codes[4][5][6][7].
🧵 3/5
It then ran SOAP collection, including SearchGalRequest bursts against the Global Address List, pulled mail from the last 90 days, and marked each day in localStorage so it would not repeat the same collection later[8][9].
🧵 4/5
CISA says Ulej sent stolen data to Flowerbed infrastructure over DNS and HTTPS, with DNS payloads Base32-encoded, split into short labels, and triggered by image requests. Defenders should patch to ZCS 10.1.13 or 10.0.18, avoid Classic webmail until patched, watch for suspicious domains and random subdomains, review localStorage for zd_comp_YYYY-MM-DD, and revoke all Application Passcodes and 2FA scratch keys if compromise is found[10][11][12][13][14][15][16][17][18].
🧵 5/5
Sign Up To Try Advanced Features
Get more accurate answers with Super Pandi, upload files, personalized discovery feed, save searches and contribute to the PandiPedia.