Exploitation of Zimbra Mail Services
An adversary is exploiting unauthenticated remote code execution vulnerabilities in Zimbra services to execute discovery commands via spawned shells or drop JSP-based webshells for persistence.
Based on research by Rapid7 2026-09-29 9 steps · 3 queries T1059.004 T1105 T1190
Brief
Why this hunt?
Zimbra servers act as the nervous system for organizational communication, making them high-value targets for adversaries. When a vulnerability like CVE-2024-45519 or CVE-2022-27925 is exploited, the impact is not limited to server compromise; it extends to the integrity of every email sent or received. Attackers use this access to manufacture reality—injecting themselves into threads or altering payment instructions—as detailed in the Rapid7 report, When Business Email Compromise Starts Rewriting Reality (https://www.rapid7.com/blog/post/ve-business-email-compromise-rewriting-reality-zimbra-cve).
Scoping the Estate
The hunt starts by scoping the environment. We query the vulnerability management surface for any Zimbra instances with unpatched, unauthenticated RCE vulnerabilities. This provides a prioritized list of hosts where exploitation is most likely to occur. While a lack of findings here is a positive sign, it is not evidence of absence, so the hunt continues to behavioral analysis.
Analyzing Behavior
The first behavioral phase examines process activity. We look for interactive shells—like bash or cmd.exe—that have a Zimbra component as their parent process. Legitimate Zimbra operations rarely require the zmjava or postjournal services to spawn a shell. When they do, it is usually for specific, known maintenance scripts. This query flags any deviation from that baseline for immediate review. In parallel, we look for persistence via the filesystem. Adversaries often drop JSP files into webapp directories to maintain access. A simple search for JSP files is too noisy, so this hunt applies a prevalence filter. We stack-count JSP files by their path and name across the entire fleet. Legitimate updates usually touch every server in a cluster, but a webshell is often unique to a single compromised host. By focusing on JSP files seen on only one or two hosts, we significantly reduce the noise of routine administration.
Triaging Evidence
The final triage phase brings these surfaces together. An analyst or agent reviews the vulnerable hosts alongside any process or file anomalies. This correlation is the core of the hunt. We look for a clear sequence: a vulnerable server, followed by a shell spawning a discovery command like whoami, or the creation of a new, unique JSP file. This evidence-based approach allows for high-confidence verdicts.
Blind Spots and Limitations
There are two primary blind spots. First, without full HTTP header logging, we cannot see the specific exploit payload if it was delivered via custom headers. Second, client-side XSS vulnerabilities execute in the user's browser. While we can see the server-side results of a hijacked session—such as changed mailbox filters—the initial exploitation remains invisible to endpoint telemetry.
In this series
Steps
-
Find vulnerable Zimbra instances
Query · scopingIdentify hosts running Zimbra versions with unauthenticated RCE or command injection vulnerabilities.
reads hb_vulnerability_findingsqlSELECT device_uid, resource_uid, cve_uid, severity, collected_at FROM hb_vulnerability_finding WHERE instr(',' || '{{zimbra_cves}}' || ',', ',' || cve_uid || ',') > 0 AND status != 'suppressed'What a hit looks like. A list of device_uids and affected resources. Silence suggests the estate is patched against the specific CVEs named in the report.
-
Shells from Zimbra components
Query · detection candidateDetect command injection by identifying shells spawned by Zimbra's java components, postjournal service, or snmp handlers.
reads hb_process_activitysqlSELECT device_hostname, process_name, process_cmd_line, parent_process_name, user_name, time FROM hb_process_activity WHERE (LOWER(parent_process_name) LIKE '%postjournal%' OR LOWER(parent_process_name) LIKE '%snmp%' OR LOWER(parent_process_name) LIKE '%zmjava%') AND (LOWER(process_name) LIKE '%/sh' OR LOWER(process_name) LIKE '%/bash' OR LOWER(process_name) LIKE '%cmd.exe' OR LOWER(process_name) LIKE '%powershell.exe') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. Process rows where a mail service component acts as the parent of an interactive shell. Benign activity includes known maintenance scripts.
-
Rare JSP files in Zimbra paths
Query · baselineFind potential webshells by stack-counting newly created JSP files within Zimbra web directories across the fleet.
reads hb_file_activitysqlSELECT file_name, file_path, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_file_activity WHERE (LOWER(file_path) LIKE '%/zimbra/%' OR LOWER(file_path) LIKE '%/webapps/%') AND (LOWER(file_name) LIKE '%.jsp' OR LOWER(file_name) LIKE '%.jspx') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY file_name, file_path HAVING hosts <= 2What a hit looks like. A JSP file found on only one or two servers. Legitimate updates usually touch the entire cluster at once; webshells are typically host-specific.
-
Triage Zimbra exploitation
Agent triageCorrelate vulnerability state with process and file anomalies to confirm unauthenticated RCE.
-
Evaluate findings
DecisionRoute to containment if the agent confirms malicious exploitation.
-
Isolate server
Response actionPrevent further movement or data theft from the compromised Zimbra instance.
-
Forensic review
Analyst taskVerify the nature of the exploit and check for mailbox filter tampering.
-
Close out
Analyst taskRecord findings and initiate patching for vulnerable but uncompromised hosts.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| Exploitation of Zimbra Public-Facing Services T1190 |
Yes | find-vulnerable-zimbra-instances, zimbra-shell-activity |
| Unauthenticated Command Execution and Webshells T1190 |
Yes | zimbra-shell-activity, rare-jsp-webshells |
| Mail Forwarding and Credential Theft T1078 · T1564 |
Out of scope | Belongs to another part of the 'When Business Email Compromise Starts Rewriting Reality' series. |
| Defense Evasion and Deception T1564 |
Out of scope | Belongs to another part of the 'When Business Email Compromise Starts Rewriting Reality' series. |
| Calendar Warfare and Document Alteration T1041 |
Out of scope | Belongs to another part of the 'When Business Email Compromise Starts Rewriting Reality' series. |
Blind spots
- Needs Full HTTP request body and custom header logging. Standard web proxy logs may not capture the specific headers used for command injection, leaving the exact injection vector unknown. It would answer whether the exploit payload was delivered via CC headers as seen in CVE-2024-45519.
- Needs hb_script_activity for client-side JavaScript execution. The XSS executes in the end-user's browser; without endpoint-browser telemetry, the exploitation is only visible through the resulting server-side actions like filter changes. It would answer whether the stored XSS in CVE-2025-27915 successfully hijacked a session.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
lookback_days | number | 14 | Days of history to examine. |
scope_hosts | list[host] | — | Filter behavioral queries to these hosts; leave empty to scan the whole estate. |
zimbra_cves | list[string] | CVE-2024-45519, CVE-2025-27915, CVE-2026-73570, CVE-2022-27925, CVE-2022-37042, CVE-2023-37580 | Zimbra vulnerabilities targeted for scoping. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
Source
---
analysis: A simple rule for shells from Java is too noisy for many server environments.
This hunt uses cross-surface correlation between vulnerability findings and filesystem
prevalence to confirm exploitation while baseline counting JSP files to filter out
legitimate administrative tools.
blind_spots:
- id: incomplete-telemetry
question: whether the exploit payload was delivered via CC headers as seen in CVE-2024-45519
requires: Full HTTP request body and custom header logging
risk: Standard web proxy logs may not capture the specific headers used for command
injection, leaving the exact injection vector unknown.
stage: initial-access-zimbra-vulnerability-exploitation
- id: browser-side-xss-execution
question: whether the stored XSS in CVE-2025-27915 successfully hijacked a session
requires: hb_script_activity for client-side JavaScript execution
risk: The XSS executes in the end-user's browser; without endpoint-browser telemetry,
the exploitation is only visible through the resulting server-side actions like
filter changes.
stage: initial-access-zimbra-vulnerability-exploitation
coverage:
- stage: initial-access-zimbra-vulnerability-exploitation
status: covered
steps:
- find-vulnerable-zimbra-instances
- zimbra-shell-activity
- stage: execution-via-command-injection-and-webshells
status: covered
steps:
- zimbra-shell-activity
- rare-jsp-webshells
- reason: Belongs to another part of the 'When Business Email Compromise Starts Rewriting
Reality' series.
stage: persistence-via-mailbox-filters-and-theft
status: out_of_scope
- reason: Belongs to another part of the 'When Business Email Compromise Starts Rewriting
Reality' series.
stage: defense-evasion-artifact-cleanup
status: out_of_scope
- reason: Belongs to another part of the 'When Business Email Compromise Starts Rewriting
Reality' series.
stage: impact-manufactured-enterprise-reality
status: out_of_scope
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: promote-to-detection
justification: Zimbra servers are critical communication hubs; unauthenticated exploitation
for RCE is currently being used in the wild to facilitate high-impact BEC and
manufactured reality scenarios.
methodology: model-assisted
trigger: intel-report
hypothesis: An adversary is exploiting unauthenticated remote code execution vulnerabilities
in Zimbra services to execute discovery commands via spawned shells or drop JSP-based
webshells for persistence.
labels:
- hunt
- attack.t1190
- attack.t1059.004
- attack.t1105
- defense evasion
- execution
- impact
- initial access
- persistence
name: Exploitation of Zimbra Mail Services
parameters:
lookback_days:
default: '14'
description: Days of history to examine.
type: number
scope_hosts:
default: []
description: Filter behavioral queries to these hosts; leave empty to scan the
whole estate.
type: list[host]
zimbra_cves:
default:
- CVE-2024-45519
- CVE-2025-27915
- CVE-2026-73570
- CVE-2022-27925
- CVE-2022-37042
- CVE-2023-37580
description: Zimbra vulnerabilities targeted for scoping.
from:
kind: article
observed: '2026-09-24'
ref: rapid7-zimbra-bec
type: list[string]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://www.rapid7.com/blog/post/ve-business-email-compromise-rewriting-reality-zimbra-cve
gates:
- dry-run
- lint
model: hb_google/gemini-3-flash-preview
rationale: Start with internet-facing Zimbra servers. If the software inventory is
outdated, widen the behavioral queries to all server hostnames.
references:
- name: "Rapid7 \u2014 When Business Email Compromise Starts Rewriting Reality"
url: https://www.rapid7.com/blog/post/ve-business-email-compromise-rewriting-reality-zimbra-cve
related:
- hunt: mailbox-persistence-and-filter-theft
reason: This hunt detects the initial breach; a follow-on hunt is required to analyze
the mailbox-level tampering that follows.
relation: follows
scenario:
stages:
- name: Exploitation of Zimbra Public-Facing Services
observables:
- CVE-2024-45519
- CVE-2025-27915
- CVE-2026-73570
- CVE-2022-27925
- CVE-2022-37042
- base64 payloads in CC fields
- .ICS calendar attachments
- SNMP notification handling
- ZIP archive uploads to mboximport
slug: initial-access-zimbra-vulnerability-exploitation
tactic: initial-access
techniques:
- T1190
- name: Unauthenticated Command Execution and Webshells
observables:
- postjournal service command injection
- JSP shell dropped on Zimbra server
- SNMP-triggered command execution
- malicious JavaScript execution via stored XSS
slug: execution-via-command-injection-and-webshells
tactic: execution
techniques:
- T1190
- name: Mail Forwarding and Credential Theft
observables:
- Quietly set mail forwarding filters
- Theft of authentication tokens
- Stealing mail and credentials
slug: persistence-via-mailbox-filters-and-theft
tactic: persistence
techniques:
- T1078
- T1564
- name: Defense Evasion and Deception
observables:
- Deleting sent messages to hide fraud
- Leaving sent messages to gaslight victims
- Modifying meetings without notification
slug: defense-evasion-artifact-cleanup
tactic: defense-evasion
techniques:
- T1564
- name: Calendar Warfare and Document Alteration
observables:
- Malicious Zoom links in calendar invites (RSVP flip)
- Fake HR memos planted in enterprise drives
- Financial summaries altered in shared drives
- Impersonating CFO/Executives without credentials
slug: impact-manufactured-enterprise-reality
tactic: impact
techniques:
- T1041
summary: Threat actors exploit various vulnerabilities in the Zimbra Collaboration
Suite to gain unauthenticated access, drop web shells, and manipulate mailbox
and calendar data. This enables 'manufactured enterprise reality' where attackers
impersonate executives, plant fraudulent documents, and use calendar invites to
launch phishing or business email compromise attacks.
series:
index: 1
slug: when-business-email-compromise-starts-rewriting-reality
title: When Business Email Compromise Starts Rewriting Reality
total: 2
severity: high
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
tlp: clear
type: investigation
---
# Exploitation of Zimbra Mail Services
This hunt identifies Zimbra infrastructure with known unauthenticated exploitation vulnerabilities and searches for two high-fidelity indicators of compromise: interactive shells spawned directly from Zimbra service components and the creation of JSP files that are unique to single hosts in the environment. By funneling vulnerability state and behavioral telemetry into a single agent triage, the hunt distinguishes between expected administrative activity and unauthenticated exploitation.
## find-vulnerable-zimbra-instances
<!-- Find vulnerable Zimbra instances -->
Identify hosts running Zimbra versions with unauthenticated RCE or command injection vulnerabilities.
```sqlite target=endpoint role=scoping params=(zimbra_cves=zimbra_cves)
~~~yaml
expected: A list of device_uids and affected resources. Silence suggests the estate
is patched against the specific CVEs named in the report.
reads:
- device_uid
- resource_uid
- cve_uid
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_uid, resource_uid, cve_uid, severity, collected_at FROM hb_vulnerability_finding WHERE instr(',' || '{{zimbra_cves}}' || ',', ',' || cve_uid || ',') > 0 AND status != 'suppressed'
```
## corroborate-activity
<!-- Corroborate activity on two surfaces -->
parallel:
- → zimbra-shell-activity
- → rare-jsp-webshells
join: → triage-exploitation
## zimbra-shell-activity
<!-- Shells from Zimbra components -->
Detect command injection by identifying shells spawned by Zimbra's java components, postjournal service, or snmp handlers.
```sqlite target=endpoint role=detection-candidate params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Process rows where a mail service component acts as the parent of an interactive
shell. Benign activity includes known maintenance scripts.
reads:
- device_hostname
- process_name
- parent_process_name
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, process_name, process_cmd_line, parent_process_name, user_name, time FROM hb_process_activity WHERE (LOWER(parent_process_name) LIKE '%postjournal%' OR LOWER(parent_process_name) LIKE '%snmp%' OR LOWER(parent_process_name) LIKE '%zmjava%') AND (LOWER(process_name) LIKE '%/sh' OR LOWER(process_name) LIKE '%/bash' OR LOWER(process_name) LIKE '%cmd.exe' OR LOWER(process_name) LIKE '%powershell.exe') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```
## rare-jsp-webshells
<!-- Rare JSP files in Zimbra paths -->
Find potential webshells by stack-counting newly created JSP files within Zimbra web directories across the fleet.
```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: A JSP file found on only one or two servers. Legitimate updates usually
touch the entire cluster at once; webshells are typically host-specific.
prevalence:
by: device_hostname
key:
- file_name
- file_path
rare_below: 3
reads:
- device_hostname
- file_name
- file_path
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT file_name, file_path, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_file_activity WHERE (LOWER(file_path) LIKE '%/zimbra/%' OR LOWER(file_path) LIKE '%/webapps/%') AND (LOWER(file_name) LIKE '%.jsp' OR LOWER(file_name) LIKE '%.jspx') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY file_name, file_path HAVING hosts <= 2
```
## triage-exploitation
<!-- Triage Zimbra exploitation -->
```agent target=hunter
cite: required
context:
- find-vulnerable-zimbra-instances
- zimbra-shell-activity
- rare-jsp-webshells
max_iterations: 6
objective: Determine if any host identified as vulnerable also displays behavioral
shell activity or unique JSP file creation. Verify if the process command lines
indicate discovery (whoami, hostname, ifconfig) or file retrieval.
success_criteria: A verdict of malicious | suspicious | benign per host, citing the
relevant rows and CVE identifiers.
tools:
- endpoint
```
## evaluate-findings
<!-- Evaluate findings -->
if~: "the triage verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-server
indeterminate: → forensic-review
unavailable: → forensic-review (blind_spot: incomplete-telemetry)
else: → close-out
## isolate-server
<!-- Isolate server -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the identified Zimbra server from the network to prevent further exploitation or lateral movement.
```
→ forensic-review
## forensic-review
<!-- Forensic review -->
```manual target=analyst
Collect the identified JSP files; verify if they are webshells. Review the postjournal and zmjava logs to identify the source IP of the exploitation. Check for new mailbox filters or forwarding rules on sensitive executive accounts.
```
→ close-out
## close-out
<!-- Close out -->
```manual target=analyst
Ensure all vulnerable hosts identified in the scoping step are scheduled for immediate patching. Record the malicious JSP hashes for global blocking.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.