{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Zimbra servers are critical communication hubs; unauthenticated exploitation for RCE is currently being used in the wild to facilitate high-impact BEC and manufactured reality scenarios."
      },
      "name": "Exploitation of Zimbra Mail Services",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1059.004",
        "attack.t1105",
        "defense evasion",
        "execution",
        "impact",
        "initial access",
        "persistence"
      ],
      "series": {
        "slug": "when-business-email-compromise-starts-rewriting-reality",
        "index": 1,
        "title": "When Business Email Compromise Starts Rewriting Reality",
        "total": 2
      },
      "related": [
        {
          "hunt": "mailbox-persistence-and-filter-theft",
          "reason": "This hunt detects the initial breach; a follow-on hunt is required to analyze the mailbox-level tampering that follows.",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A simple rule for shells from Java is too noisy for many server environments. This hunt uses cross-surface correlation between vulnerability findings and filesystem prevalence to confirm exploitation while baseline counting JSP files to filter out legitimate administrative tools.",
      "coverage": [
        {
          "stage": "initial-access-zimbra-vulnerability-exploitation",
          "steps": [
            "find-vulnerable-zimbra-instances",
            "zimbra-shell-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "execution-via-command-injection-and-webshells",
          "steps": [
            "zimbra-shell-activity",
            "rare-jsp-webshells"
          ],
          "status": "covered"
        },
        {
          "stage": "persistence-via-mailbox-filters-and-theft",
          "reason": "Belongs to another part of the 'When Business Email Compromise Starts Rewriting Reality' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "defense-evasion-artifact-cleanup",
          "reason": "Belongs to another part of the 'When Business Email Compromise Starts Rewriting Reality' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "impact-manufactured-enterprise-reality",
          "reason": "Belongs to another part of the 'When Business Email Compromise Starts Rewriting Reality' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Exploitation of Zimbra Public-Facing Services",
            "slug": "initial-access-zimbra-vulnerability-exploitation",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "CVE-2024-45519",
              "CVE-2025-27915",
              "CVE-2026-73570",
              "CVE-2022-27925",
              "CVE-2022-37042",
              "base64 payloads in CC fields",
              ".ICS calendar attachments",
              "SNMP notification handling",
              "ZIP archive uploads to mboximport"
            ]
          },
          {
            "name": "Unauthenticated Command Execution and Webshells",
            "slug": "execution-via-command-injection-and-webshells",
            "tactic": "execution",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "postjournal service command injection",
              "JSP shell dropped on Zimbra server",
              "SNMP-triggered command execution",
              "malicious JavaScript execution via stored XSS"
            ]
          },
          {
            "name": "Mail Forwarding and Credential Theft",
            "slug": "persistence-via-mailbox-filters-and-theft",
            "tactic": "persistence",
            "techniques": [
              "T1078",
              "T1564"
            ],
            "observables": [
              "Quietly set mail forwarding filters",
              "Theft of authentication tokens",
              "Stealing mail and credentials"
            ]
          },
          {
            "name": "Defense Evasion and Deception",
            "slug": "defense-evasion-artifact-cleanup",
            "tactic": "defense-evasion",
            "techniques": [
              "T1564"
            ],
            "observables": [
              "Deleting sent messages to hide fraud",
              "Leaving sent messages to gaslight victims",
              "Modifying meetings without notification"
            ]
          },
          {
            "name": "Calendar Warfare and Document Alteration",
            "slug": "impact-manufactured-enterprise-reality",
            "tactic": "impact",
            "techniques": [
              "T1041"
            ],
            "observables": [
              "Malicious Zoom links in calendar invites (RSVP flip)",
              "Fake HR memos planted in enterprise drives",
              "Financial summaries altered in shared drives",
              "Impersonating CFO/Executives without credentials"
            ]
          }
        ],
        "summary": "Threat actors exploit various vulnerabilities in the Zimbra Collaboration Suite to gain unauthenticated access, drop web shells, and manipulate mailbox and calendar data. This enables 'manufactured enterprise reality' where attackers impersonate executives, plant fraudulent documents, and use calendar invites to launch phishing or business email compromise attacks."
      },
      "severity": "high",
      "rationale": "Start with internet-facing Zimbra servers. If the software inventory is outdated, widen the behavioral queries to all server hostnames.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary is exploiting unauthenticated remote code execution vulnerabilities in Zimbra services to execute discovery commands via spawned shells or drop JSP-based webshells for persistence.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Filter behavioral queries to these hosts; leave empty to scan the whole estate."
        },
        "zimbra_cves": {
          "from": {
            "ref": "rapid7-zimbra-bec",
            "kind": "article",
            "observed": "2026-09-24"
          },
          "type": "list[string]",
          "default": [
            "CVE-2024-45519",
            "CVE-2025-27915",
            "CVE-2026-73570",
            "CVE-2022-27925",
            "CVE-2022-37042",
            "CVE-2023-37580"
          ],
          "description": "Zimbra vulnerabilities targeted for scoping."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.rapid7.com/blog/post/ve-business-email-compromise-rewriting-reality-zimbra-cve",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.rapid7.com/blog/post/ve-business-email-compromise-rewriting-reality-zimbra-cve",
          "name": "Rapid7 \u2014 When Business Email Compromise Starts Rewriting Reality"
        }
      ],
      "blind_spots": [
        {
          "id": "incomplete-telemetry",
          "risk": "Standard web proxy logs may not capture the specific headers used for command injection, leaving the exact injection vector unknown.",
          "stage": "initial-access-zimbra-vulnerability-exploitation",
          "question": "whether the exploit payload was delivered via CC headers as seen in CVE-2024-45519",
          "requires": "Full HTTP request body and custom header logging"
        },
        {
          "id": "browser-side-xss-execution",
          "risk": "The XSS executes in the end-user's browser; without endpoint-browser telemetry, the exploitation is only visible through the resulting server-side actions like filter changes.",
          "stage": "initial-access-zimbra-vulnerability-exploitation",
          "question": "whether the stored XSS in CVE-2025-27915 successfully hijacked a session",
          "requires": "hb_script_activity for client-side JavaScript execution"
        }
      ]
    },
    "name": "Exploitation of Zimbra Mail Services",
    "description": "This hunt identifies Zimbra infrastructure with known unauthenticated exploitation vulnerabilities and searches for two high-fidelity indicators of compromise: interactive shells spawned directly from Zimbra service components and the creation of JSP files that are unique to single hosts in the environment. By funneling vulnerability state and behavioral telemetry into a single agent triage, the hunt distinguishes between expected administrative activity and unauthenticated exploitation."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "when-business-email-compromise-starts-rewriting-reality",
          "index": 1,
          "title": "When Business Email Compromise Starts Rewriting Reality",
          "total": 2
        },
        "coverage": [
          {
            "stage": "initial-access-zimbra-vulnerability-exploitation",
            "steps": [
              "find-vulnerable-zimbra-instances",
              "zimbra-shell-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "execution-via-command-injection-and-webshells",
            "steps": [
              "zimbra-shell-activity",
              "rare-jsp-webshells"
            ],
            "status": "covered"
          },
          {
            "stage": "persistence-via-mailbox-filters-and-theft",
            "reason": "Belongs to another part of the 'When Business Email Compromise Starts Rewriting Reality' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "defense-evasion-artifact-cleanup",
            "reason": "Belongs to another part of the 'When Business Email Compromise Starts Rewriting Reality' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "impact-manufactured-enterprise-reality",
            "reason": "Belongs to another part of the 'When Business Email Compromise Starts Rewriting Reality' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary is exploiting unauthenticated remote code execution vulnerabilities in Zimbra services to execute discovery commands via spawned shells or drop JSP-based webshells for persistence.",
        "blind_spots": [
          {
            "id": "incomplete-telemetry",
            "risk": "Standard web proxy logs may not capture the specific headers used for command injection, leaving the exact injection vector unknown.",
            "stage": "initial-access-zimbra-vulnerability-exploitation",
            "question": "whether the exploit payload was delivered via CC headers as seen in CVE-2024-45519",
            "requires": "Full HTTP request body and custom header logging"
          },
          {
            "id": "browser-side-xss-execution",
            "risk": "The XSS executes in the end-user's browser; without endpoint-browser telemetry, the exploitation is only visible through the resulting server-side actions like filter changes.",
            "stage": "initial-access-zimbra-vulnerability-exploitation",
            "question": "whether the stored XSS in CVE-2025-27915 successfully hijacked a session",
            "requires": "hb_script_activity for client-side JavaScript execution"
          }
        ],
        "scoping_notes": "Start with internet-facing Zimbra servers. If the software inventory is outdated, widen the behavioral queries to all server hostnames.",
        "beyond_detection": "A simple rule for shells from Java is too noisy for many server environments. This hunt uses cross-surface correlation between vulnerability findings and filesystem prevalence to confirm exploitation while baseline counting JSP files to filter out legitimate administrative tools."
      }
    },
    {
      "id": "find-vulnerable-zimbra-instances",
      "type": "query",
      "label": "Find vulnerable Zimbra instances",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_uid, resource_uid, cve_uid, severity, collected_at FROM hb_vulnerability_finding WHERE instr(',' || '{{zimbra_cves}}' || ',', ',' || cve_uid || ',') > 0 AND status != 'suppressed'",
        "surface": "hb_vulnerability_finding",
        "description": "Identify hosts running Zimbra versions with unauthenticated RCE or command injection vulnerabilities.",
        "expected_signal": "A list of device_uids and affected resources. Silence suggests the estate is patched against the specific CVEs named in the report."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Find vulnerable Zimbra instances",
        "reads": [
          "device_uid",
          "resource_uid",
          "cve_uid"
        ],
        "source": "hb_vulnerability_finding",
        "target": "endpoint",
        "content": "SELECT device_uid, resource_uid, cve_uid, severity, collected_at FROM hb_vulnerability_finding WHERE instr(',' || '{{zimbra_cves}}' || ',', ',' || cve_uid || ',') > 0 AND status != 'suppressed'",
        "silence": "not_evidence_of_absence",
        "expected": "A list of device_uids and affected resources. Silence suggests the estate is patched against the specific CVEs named in the report.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "zimbra-shell-activity",
      "type": "query",
      "label": "Shells from Zimbra components",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, parent_process_name, user_name, time FROM hb_process_activity WHERE (LOWER(parent_process_name) LIKE '%postjournal%' OR LOWER(parent_process_name) LIKE '%snmp%' OR LOWER(parent_process_name) LIKE '%zmjava%') AND (LOWER(process_name) LIKE '%/sh' OR LOWER(process_name) LIKE '%/bash' OR LOWER(process_name) LIKE '%cmd.exe' OR LOWER(process_name) LIKE '%powershell.exe') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Detect command injection by identifying shells spawned by Zimbra's java components, postjournal service, or snmp handlers.",
        "expected_signal": "Process rows where a mail service component acts as the parent of an interactive shell. Benign activity includes known maintenance scripts."
      },
      "parents": [
        {
          "id": "find-vulnerable-zimbra-instances"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Shells from Zimbra components",
        "reads": [
          "device_hostname",
          "process_name",
          "parent_process_name"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, parent_process_name, user_name, time FROM hb_process_activity WHERE (LOWER(parent_process_name) LIKE '%postjournal%' OR LOWER(parent_process_name) LIKE '%snmp%' OR LOWER(parent_process_name) LIKE '%zmjava%') AND (LOWER(process_name) LIKE '%/sh' OR LOWER(process_name) LIKE '%/bash' OR LOWER(process_name) LIKE '%cmd.exe' OR LOWER(process_name) LIKE '%powershell.exe') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Process rows where a mail service component acts as the parent of an interactive shell. Benign activity includes known maintenance scripts.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "rare-jsp-webshells",
      "type": "query",
      "label": "Rare JSP files in Zimbra paths",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT file_name, file_path, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_file_activity WHERE (LOWER(file_path) LIKE '%/zimbra/%' OR LOWER(file_path) LIKE '%/webapps/%') AND (LOWER(file_name) LIKE '%.jsp' OR LOWER(file_name) LIKE '%.jspx') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY file_name, file_path HAVING hosts <= 2",
        "surface": "hb_file_activity",
        "description": "Find potential webshells by stack-counting newly created JSP files within Zimbra web directories across the fleet.",
        "expected_signal": "A JSP file found on only one or two servers. Legitimate updates usually touch the entire cluster at once; webshells are typically host-specific."
      },
      "parents": [
        {
          "id": "find-vulnerable-zimbra-instances"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare JSP files in Zimbra paths",
        "reads": [
          "device_hostname",
          "file_name",
          "file_path"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT file_name, file_path, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_file_activity WHERE (LOWER(file_path) LIKE '%/zimbra/%' OR LOWER(file_path) LIKE '%/webapps/%') AND (LOWER(file_name) LIKE '%.jsp' OR LOWER(file_name) LIKE '%.jspx') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY file_name, file_path HAVING hosts <= 2",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A JSP file found on only one or two servers. Legitimate updates usually touch the entire cluster at once; webshells are typically host-specific.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "file_name",
            "file_path"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "triage-exploitation",
      "type": "analytic",
      "label": "Triage Zimbra exploitation",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "find-vulnerable-zimbra-instances",
          "zimbra-shell-activity",
          "rare-jsp-webshells"
        ],
        "objective": "Determine if any host identified as vulnerable also displays behavioral shell activity or unique JSP file creation. Verify if the process command lines indicate discovery (whoami, hostname, ifconfig) or file retrieval.",
        "description": "Correlate vulnerability state with process and file anomalies to confirm unauthenticated RCE.",
        "max_iterations": 6,
        "expected_signal": "A host-by-host verdict distinguishing between vulnerability-only results and active exploitation.",
        "success_criteria": "A verdict of malicious | suspicious | benign per host, citing the relevant rows and CVE identifiers."
      },
      "parents": [
        {
          "id": "zimbra-shell-activity",
          "kind": "merge"
        },
        {
          "id": "rare-jsp-webshells",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "evaluate-findings",
      "type": "checkpoint",
      "label": "Evaluate findings",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict is malicious for at least one host",
        "condition": "the triage verdict is malicious for at least one host",
        "blind_spot": "incomplete-telemetry",
        "confidence": "high",
        "description": "Route to containment if the agent confirms malicious exploitation.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-exploitation"
        }
      ]
    },
    {
      "id": "isolate-server",
      "type": "action",
      "label": "Isolate server",
      "config": {
        "target": "endpoint",
        "description": "Prevent further movement or data theft from the compromised Zimbra instance.",
        "instructions": "Isolate the identified Zimbra server from the network to prevent further exploitation or lateral movement.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "evaluate-findings",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "forensic-review",
      "type": "task",
      "label": "Forensic review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the nature of the exploit and check for mailbox filter tampering.",
        "instructions": "Collect the identified JSP files; verify if they are webshells. Review the postjournal and zmjava logs to identify the source IP of the exploitation. Check for new mailbox filters or forwarding rules on sensitive executive accounts."
      },
      "parents": [
        {
          "id": "evaluate-findings",
          "branch": "default"
        },
        {
          "id": "evaluate-findings",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-server"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out",
      "config": {
        "assignee": "analyst",
        "description": "Record findings and initiate patching for vulnerable but uncompromised hosts.",
        "instructions": "Ensure all vulnerable hosts identified in the scoping step are scheduled for immediate patching. Record the malicious JSP hashes for global blocking."
      },
      "parents": [
        {
          "id": "evaluate-findings",
          "branch": "on_refutes"
        },
        {
          "id": "forensic-review"
        }
      ]
    }
  ]
}