---
analysis: A simple rule for shells from Java is too noisy for many server environments.
  This hunt uses cross-surface correlation between vulnerability findings and filesystem
  prevalence to confirm exploitation while baseline counting JSP files to filter out
  legitimate administrative tools.
blind_spots:
- id: incomplete-telemetry
  question: whether the exploit payload was delivered via CC headers as seen in CVE-2024-45519
  requires: Full HTTP request body and custom header logging
  risk: Standard web proxy logs may not capture the specific headers used for command
    injection, leaving the exact injection vector unknown.
  stage: initial-access-zimbra-vulnerability-exploitation
- id: browser-side-xss-execution
  question: whether the stored XSS in CVE-2025-27915 successfully hijacked a session
  requires: hb_script_activity for client-side JavaScript execution
  risk: The XSS executes in the end-user's browser; without endpoint-browser telemetry,
    the exploitation is only visible through the resulting server-side actions like
    filter changes.
  stage: initial-access-zimbra-vulnerability-exploitation
coverage:
- stage: initial-access-zimbra-vulnerability-exploitation
  status: covered
  steps:
  - find-vulnerable-zimbra-instances
  - zimbra-shell-activity
- stage: execution-via-command-injection-and-webshells
  status: covered
  steps:
  - zimbra-shell-activity
  - rare-jsp-webshells
- reason: Belongs to another part of the 'When Business Email Compromise Starts Rewriting
    Reality' series.
  stage: persistence-via-mailbox-filters-and-theft
  status: out_of_scope
- reason: Belongs to another part of the 'When Business Email Compromise Starts Rewriting
    Reality' series.
  stage: defense-evasion-artifact-cleanup
  status: out_of_scope
- reason: Belongs to another part of the 'When Business Email Compromise Starts Rewriting
    Reality' series.
  stage: impact-manufactured-enterprise-reality
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: Zimbra servers are critical communication hubs; unauthenticated exploitation
    for RCE is currently being used in the wild to facilitate high-impact BEC and
    manufactured reality scenarios.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An adversary is exploiting unauthenticated remote code execution vulnerabilities
  in Zimbra services to execute discovery commands via spawned shells or drop JSP-based
  webshells for persistence.
labels:
- hunt
- attack.t1190
- attack.t1059.004
- attack.t1105
- defense evasion
- execution
- impact
- initial access
- persistence
name: Exploitation of Zimbra Mail Services
parameters:
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  scope_hosts:
    default: []
    description: Filter behavioral queries to these hosts; leave empty to scan the
      whole estate.
    type: list[host]
  zimbra_cves:
    default:
    - CVE-2024-45519
    - CVE-2025-27915
    - CVE-2026-73570
    - CVE-2022-27925
    - CVE-2022-37042
    - CVE-2023-37580
    description: Zimbra vulnerabilities targeted for scoping.
    from:
      kind: article
      observed: '2026-09-24'
      ref: rapid7-zimbra-bec
    type: list[string]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.rapid7.com/blog/post/ve-business-email-compromise-rewriting-reality-zimbra-cve
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Start with internet-facing Zimbra servers. If the software inventory is
  outdated, widen the behavioral queries to all server hostnames.
references:
- name: "Rapid7 \u2014 When Business Email Compromise Starts Rewriting Reality"
  url: https://www.rapid7.com/blog/post/ve-business-email-compromise-rewriting-reality-zimbra-cve
related:
- hunt: mailbox-persistence-and-filter-theft
  reason: This hunt detects the initial breach; a follow-on hunt is required to analyze
    the mailbox-level tampering that follows.
  relation: follows
scenario:
  stages:
  - name: Exploitation of Zimbra Public-Facing Services
    observables:
    - CVE-2024-45519
    - CVE-2025-27915
    - CVE-2026-73570
    - CVE-2022-27925
    - CVE-2022-37042
    - base64 payloads in CC fields
    - .ICS calendar attachments
    - SNMP notification handling
    - ZIP archive uploads to mboximport
    slug: initial-access-zimbra-vulnerability-exploitation
    tactic: initial-access
    techniques:
    - T1190
  - name: Unauthenticated Command Execution and Webshells
    observables:
    - postjournal service command injection
    - JSP shell dropped on Zimbra server
    - SNMP-triggered command execution
    - malicious JavaScript execution via stored XSS
    slug: execution-via-command-injection-and-webshells
    tactic: execution
    techniques:
    - T1190
  - name: Mail Forwarding and Credential Theft
    observables:
    - Quietly set mail forwarding filters
    - Theft of authentication tokens
    - Stealing mail and credentials
    slug: persistence-via-mailbox-filters-and-theft
    tactic: persistence
    techniques:
    - T1078
    - T1564
  - name: Defense Evasion and Deception
    observables:
    - Deleting sent messages to hide fraud
    - Leaving sent messages to gaslight victims
    - Modifying meetings without notification
    slug: defense-evasion-artifact-cleanup
    tactic: defense-evasion
    techniques:
    - T1564
  - name: Calendar Warfare and Document Alteration
    observables:
    - Malicious Zoom links in calendar invites (RSVP flip)
    - Fake HR memos planted in enterprise drives
    - Financial summaries altered in shared drives
    - Impersonating CFO/Executives without credentials
    slug: impact-manufactured-enterprise-reality
    tactic: impact
    techniques:
    - T1041
  summary: Threat actors exploit various vulnerabilities in the Zimbra Collaboration
    Suite to gain unauthenticated access, drop web shells, and manipulate mailbox
    and calendar data. This enables 'manufactured enterprise reality' where attackers
    impersonate executives, plant fraudulent documents, and use calendar invites to
    launch phishing or business email compromise attacks.
series:
  index: 1
  slug: when-business-email-compromise-starts-rewriting-reality
  title: When Business Email Compromise Starts Rewriting Reality
  total: 2
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
tlp: clear
type: investigation
---


# Exploitation of Zimbra Mail Services

This hunt identifies Zimbra infrastructure with known unauthenticated exploitation vulnerabilities and searches for two high-fidelity indicators of compromise: interactive shells spawned directly from Zimbra service components and the creation of JSP files that are unique to single hosts in the environment. By funneling vulnerability state and behavioral telemetry into a single agent triage, the hunt distinguishes between expected administrative activity and unauthenticated exploitation.

## find-vulnerable-zimbra-instances
<!-- Find vulnerable Zimbra instances -->
Identify hosts running Zimbra versions with unauthenticated RCE or command injection vulnerabilities.

```sqlite target=endpoint role=scoping params=(zimbra_cves=zimbra_cves)
~~~yaml
expected: A list of device_uids and affected resources. Silence suggests the estate
  is patched against the specific CVEs named in the report.
reads:
- device_uid
- resource_uid
- cve_uid
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_uid, resource_uid, cve_uid, severity, collected_at FROM hb_vulnerability_finding WHERE instr(',' || '{{zimbra_cves}}' || ',', ',' || cve_uid || ',') > 0 AND status != 'suppressed'
```

## corroborate-activity
<!-- Corroborate activity on two surfaces -->
parallel:
- → zimbra-shell-activity
- → rare-jsp-webshells
join: → triage-exploitation

## zimbra-shell-activity
<!-- Shells from Zimbra components -->
Detect command injection by identifying shells spawned by Zimbra's java components, postjournal service, or snmp handlers.

```sqlite target=endpoint role=detection-candidate params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Process rows where a mail service component acts as the parent of an interactive
  shell. Benign activity includes known maintenance scripts.
reads:
- device_hostname
- process_name
- parent_process_name
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, process_name, process_cmd_line, parent_process_name, user_name, time FROM hb_process_activity WHERE (LOWER(parent_process_name) LIKE '%postjournal%' OR LOWER(parent_process_name) LIKE '%snmp%' OR LOWER(parent_process_name) LIKE '%zmjava%') AND (LOWER(process_name) LIKE '%/sh' OR LOWER(process_name) LIKE '%/bash' OR LOWER(process_name) LIKE '%cmd.exe' OR LOWER(process_name) LIKE '%powershell.exe') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## rare-jsp-webshells
<!-- Rare JSP files in Zimbra paths -->
Find potential webshells by stack-counting newly created JSP files within Zimbra web directories across the fleet.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: A JSP file found on only one or two servers. Legitimate updates usually
  touch the entire cluster at once; webshells are typically host-specific.
prevalence:
  by: device_hostname
  key:
  - file_name
  - file_path
  rare_below: 3
reads:
- device_hostname
- file_name
- file_path
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT file_name, file_path, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_file_activity WHERE (LOWER(file_path) LIKE '%/zimbra/%' OR LOWER(file_path) LIKE '%/webapps/%') AND (LOWER(file_name) LIKE '%.jsp' OR LOWER(file_name) LIKE '%.jspx') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY file_name, file_path HAVING hosts <= 2
```

## triage-exploitation
<!-- Triage Zimbra exploitation -->
```agent target=hunter
cite: required
context:
- find-vulnerable-zimbra-instances
- zimbra-shell-activity
- rare-jsp-webshells
max_iterations: 6
objective: Determine if any host identified as vulnerable also displays behavioral
  shell activity or unique JSP file creation. Verify if the process command lines
  indicate discovery (whoami, hostname, ifconfig) or file retrieval.
success_criteria: A verdict of malicious | suspicious | benign per host, citing the
  relevant rows and CVE identifiers.
tools:
- endpoint
```

## evaluate-findings
<!-- Evaluate findings -->
if~: "the triage verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-server
indeterminate: → forensic-review
unavailable: → forensic-review (blind_spot: incomplete-telemetry)
else: → close-out

## isolate-server
<!-- Isolate server -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the identified Zimbra server from the network to prevent further exploitation or lateral movement.
```
→ forensic-review

## forensic-review
<!-- Forensic review -->
```manual target=analyst
Collect the identified JSP files; verify if they are webshells. Review the postjournal and zmjava logs to identify the source IP of the exploitation. Check for new mailbox filters or forwarding rules on sensitive executive accounts.
```
→ close-out

## close-out
<!-- Close out -->
```manual target=analyst
Ensure all vulnerable hosts identified in the scoping step are scheduled for immediate patching. Record the malicious JSP hashes for global blocking.
```
→ end
