{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Zimbra servers are primary systems of record for the business; compromise allows attackers to manipulate organizational trust and conduct high-stakes fraud by rewriting the digital history of the company."
      },
      "name": "Zimbra BEC: Manufactured Reality and Manipulation",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1078",
        "attack.t1564",
        "attack.t1041",
        "attack.t1190",
        "defense evasion",
        "execution",
        "impact",
        "initial access",
        "persistence"
      ],
      "series": {
        "slug": "when-business-email-compromise-starts-rewriting-reality",
        "index": 2,
        "title": "When Business Email Compromise Starts Rewriting Reality",
        "total": 2
      },
      "related": [
        {
          "hunt": "zimbra-exploitation-webshells",
          "reason": "Initial exploitation and webshell persistence are handled by a separate behavioral hunt focusing on exploit artifacts.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "exploitation-of-zimbra-mail-services",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A standard rule might detect the initial exploit, but this hunt pivots to the manufactured reality phase. It uses a prevalence baseline to identify rare admin commands and correlates them with anomalous server-initiated connections to meeting platforms, which a single rule cannot effectively combine.",
      "coverage": [
        {
          "stage": "persistence-via-mailbox-filters-and-theft",
          "steps": [
            "forwarding-prevalence"
          ],
          "status": "covered"
        },
        {
          "stage": "defense-evasion-artifact-cleanup",
          "reason": "Deleting sent items or modifying RSVP status happens within the application internal database and is not exposed to OS-layer surfaces.",
          "status": "not_visible",
          "blind_spot": "app-internal-manipulation"
        },
        {
          "stage": "impact-manufactured-enterprise-reality",
          "steps": [
            "meeting-connections"
          ],
          "status": "covered"
        },
        {
          "stage": "initial-access-zimbra-vulnerability-exploitation",
          "reason": "Belongs to another part of the 'When Business Email Compromise Starts Rewriting Reality' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "execution-via-command-injection-and-webshells",
          "reason": "Belongs to another part of the 'When Business Email Compromise Starts Rewriting Reality' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Exploitation of Zimbra Public-Facing Services",
            "slug": "initial-access-zimbra-vulnerability-exploitation",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "CVE-2024-45519",
              "CVE-2025-27915",
              "CVE-2026-73570",
              "CVE-2022-27925",
              "CVE-2022-37042",
              "base64 payloads in CC fields",
              ".ICS calendar attachments",
              "SNMP notification handling",
              "ZIP archive uploads to mboximport"
            ]
          },
          {
            "name": "Unauthenticated Command Execution and Webshells",
            "slug": "execution-via-command-injection-and-webshells",
            "tactic": "execution",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "postjournal service command injection",
              "JSP shell dropped on Zimbra server",
              "SNMP-triggered command execution",
              "malicious JavaScript execution via stored XSS"
            ]
          },
          {
            "name": "Mail Forwarding and Credential Theft",
            "slug": "persistence-via-mailbox-filters-and-theft",
            "tactic": "persistence",
            "techniques": [
              "T1078",
              "T1564"
            ],
            "observables": [
              "Quietly set mail forwarding filters",
              "Theft of authentication tokens",
              "Stealing mail and credentials"
            ]
          },
          {
            "name": "Defense Evasion and Deception",
            "slug": "defense-evasion-artifact-cleanup",
            "tactic": "defense-evasion",
            "techniques": [
              "T1564"
            ],
            "observables": [
              "Deleting sent messages to hide fraud",
              "Leaving sent messages to gaslight victims",
              "Modifying meetings without notification"
            ]
          },
          {
            "name": "Calendar Warfare and Document Alteration",
            "slug": "impact-manufactured-enterprise-reality",
            "tactic": "impact",
            "techniques": [
              "T1041"
            ],
            "observables": [
              "Malicious Zoom links in calendar invites (RSVP flip)",
              "Fake HR memos planted in enterprise drives",
              "Financial summaries altered in shared drives",
              "Impersonating CFO/Executives without credentials"
            ]
          }
        ],
        "summary": "Threat actors exploit various vulnerabilities in the Zimbra Collaboration Suite to gain unauthenticated access, drop web shells, and manipulate mailbox and calendar data. This enables 'manufactured enterprise reality' where attackers impersonate executives, plant fraudulent documents, and use calendar invites to launch phishing or business email compromise attacks."
      },
      "severity": "high",
      "rationale": "Focus on identified authoritative Zimbra servers. Use software inventory to list them. Filter the process and network queries by these hostnames to minimize noise from user workstations.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An attacker has compromised a Zimbra server and is manipulating organizational trust by configuring unauthorized mail forwarding and initiating outbound connections to meeting platforms to facilitate social engineering.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Optional list of Zimbra server hostnames to focus the hunt."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine for manipulation activity."
        },
        "meeting_domains": {
          "from": {
            "ref": "https://www.rapid7.com/blog/post/ve-business-email-compromise-rewriting-reality-zimbra-cve",
            "kind": "article",
            "observed": "2026-09-24"
          },
          "type": "list[domain]",
          "default": [
            "zoom.us",
            "zoom.com",
            "webex.com",
            "teams.microsoft.com",
            "meet.google.com"
          ],
          "description": "Domains for meeting platforms used in calendar warfare scenarios."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.rapid7.com/blog/post/ve-business-email-compromise-rewriting-reality-zimbra-cve",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.rapid7.com/blog/post/ve-business-email-compromise-rewriting-reality-zimbra-cve",
          "name": "Rapid7 \u2014 When Business Email Compromise Starts Rewriting Reality"
        }
      ],
      "blind_spots": [
        {
          "id": "app-internal-manipulation",
          "risk": "These actions occur within the Zimbra database and are invisible to OS-layer process or file monitoring, allowing attackers to gaslight victims without leaving a system log trail.",
          "owner": "Mail Platform Team",
          "stage": "defense-evasion-artifact-cleanup",
          "question": "Did the attacker delete sent items or flip RSVP statuses internally?",
          "requires": "Zimbra application audit logs",
          "remediation": "Enable and ingest Zimbra mailbox auditing logs into the central SIEM."
        },
        {
          "id": "missing-file-content-visibility",
          "risk": "File activity shows that a file was modified but not whether the modification was a legitimate update or a malicious alteration by an attacker impersonating a user.",
          "owner": "DLP/Security Team",
          "stage": "impact-manufactured-enterprise-reality",
          "question": "Is the content of an altered financial summary fraudulent?",
          "requires": "Document content inspection",
          "remediation": "Deploy file integrity monitoring or content inspection for sensitive shared drive paths."
        }
      ]
    },
    "name": "Zimbra BEC: Manufactured Reality and Manipulation",
    "description": "This hunt targets the manufactured reality phase of Business Email Compromise (BEC) within Zimbra environments. Unlike simple data theft, this attack involves altering the organization's system of record to gaslight users and facilitate fraud. We hunt for two primary behavioral indicators: the use of Zimbra administrative tools to silently configure mail forwarding and server-initiated network connections to meeting platforms like Zoom. These patterns indicate an attacker is actively shaping the communication environment to prop up fraudulent narratives."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "when-business-email-compromise-starts-rewriting-reality",
          "index": 2,
          "title": "When Business Email Compromise Starts Rewriting Reality",
          "total": 2
        },
        "coverage": [
          {
            "stage": "persistence-via-mailbox-filters-and-theft",
            "steps": [
              "forwarding-prevalence"
            ],
            "status": "covered"
          },
          {
            "stage": "defense-evasion-artifact-cleanup",
            "reason": "Deleting sent items or modifying RSVP status happens within the application internal database and is not exposed to OS-layer surfaces.",
            "status": "not_visible",
            "blind_spot": "app-internal-manipulation"
          },
          {
            "stage": "impact-manufactured-enterprise-reality",
            "steps": [
              "meeting-connections"
            ],
            "status": "covered"
          },
          {
            "stage": "initial-access-zimbra-vulnerability-exploitation",
            "reason": "Belongs to another part of the 'When Business Email Compromise Starts Rewriting Reality' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "execution-via-command-injection-and-webshells",
            "reason": "Belongs to another part of the 'When Business Email Compromise Starts Rewriting Reality' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An attacker has compromised a Zimbra server and is manipulating organizational trust by configuring unauthorized mail forwarding and initiating outbound connections to meeting platforms to facilitate social engineering.",
        "blind_spots": [
          {
            "id": "app-internal-manipulation",
            "risk": "These actions occur within the Zimbra database and are invisible to OS-layer process or file monitoring, allowing attackers to gaslight victims without leaving a system log trail.",
            "owner": "Mail Platform Team",
            "stage": "defense-evasion-artifact-cleanup",
            "question": "Did the attacker delete sent items or flip RSVP statuses internally?",
            "requires": "Zimbra application audit logs",
            "remediation": "Enable and ingest Zimbra mailbox auditing logs into the central SIEM."
          },
          {
            "id": "missing-file-content-visibility",
            "risk": "File activity shows that a file was modified but not whether the modification was a legitimate update or a malicious alteration by an attacker impersonating a user.",
            "owner": "DLP/Security Team",
            "stage": "impact-manufactured-enterprise-reality",
            "question": "Is the content of an altered financial summary fraudulent?",
            "requires": "Document content inspection",
            "remediation": "Deploy file integrity monitoring or content inspection for sensitive shared drive paths."
          }
        ],
        "scoping_notes": "Focus on identified authoritative Zimbra servers. Use software inventory to list them. Filter the process and network queries by these hostnames to minimize noise from user workstations.",
        "beyond_detection": "A standard rule might detect the initial exploit, but this hunt pivots to the manufactured reality phase. It uses a prevalence baseline to identify rare admin commands and correlates them with anomalous server-initiated connections to meeting platforms, which a single rule cannot effectively combine."
      }
    },
    {
      "id": "identify-zimbra-servers",
      "type": "query",
      "label": "Identify Zimbra collaboration servers",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version, vendor_name FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%zimbra%' OR LOWER(vendor_name) LIKE '%zimbra%')",
        "surface": "hb_software_inventory",
        "description": "Identify the hosts running Zimbra to narrow the behavioral hunt to the mail backbone.",
        "expected_signal": "A list of hostnames acting as the Zimbra server. Silence indicates Zimbra is not managed or not present in software inventory."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify Zimbra collaboration servers",
        "reads": [
          "device_hostname",
          "package_name",
          "package_version",
          "vendor_name"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version, vendor_name FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%zimbra%' OR LOWER(vendor_name) LIKE '%zimbra%')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hostnames acting as the Zimbra server. Silence indicates Zimbra is not managed or not present in software inventory.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "forwarding-prevalence",
      "type": "query",
      "label": "Prevalence of mail forwarding commands",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT process_cmd_line, COUNT(DISTINCT device_hostname) AS hosts, COUNT(*) AS runs, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%zmprov%' AND (LOWER(process_cmd_line) LIKE '%modifyaccount%' OR LOWER(process_cmd_line) LIKE '%zimbraMailForwardingAddress%')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_cmd_line HAVING hosts <= 3 ORDER BY hosts ASC, runs DESC",
        "surface": "hb_process_activity",
        "description": "Stack-count administrative commands that set mail forwarding to identify rare or unauthorized redirection across the Zimbra fleet.",
        "expected_signal": "Command lines redirected mail for specific users. A low host count suggests an attacker targeting specific mailboxes rather than global policy changes."
      },
      "parents": [
        {
          "id": "identify-zimbra-servers"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Prevalence of mail forwarding commands",
        "reads": [
          "device_hostname",
          "process_cmd_line",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT process_cmd_line, COUNT(DISTINCT device_hostname) AS hosts, COUNT(*) AS runs, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%zmprov%' AND (LOWER(process_cmd_line) LIKE '%modifyaccount%' OR LOWER(process_cmd_line) LIKE '%zimbraMailForwardingAddress%')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_cmd_line HAVING hosts <= 3 ORDER BY hosts ASC, runs DESC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Command lines redirected mail for specific users. A low host count suggests an attacker targeting specific mailboxes rather than global policy changes.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_cmd_line"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "meeting-connections",
      "type": "query",
      "label": "Suspicious meeting platform connections",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "network",
        "content": "SELECT device_hostname, dst_endpoint_hostname, process_name, COUNT(*) AS connections, MIN(time) AS first_seen FROM hb_network_connection WHERE (instr(',' || '{{meeting_domains}}' || ',', ',' || LOWER(dst_endpoint_hostname) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, dst_endpoint_hostname, process_name ORDER BY connections DESC",
        "surface": "hb_network_connection",
        "description": "Identify Zimbra servers initiating connections to external meeting platforms, indicating potential calendar invitation manipulation.",
        "expected_signal": "Connections from the Zimbra backend to Zoom, Teams, or Google Meet. Servers typically do not connect to these directly; users do from endpoints."
      },
      "parents": [
        {
          "id": "identify-zimbra-servers"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Suspicious meeting platform connections",
        "reads": [
          "device_hostname",
          "dst_endpoint_hostname",
          "process_name",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT device_hostname, dst_endpoint_hostname, process_name, COUNT(*) AS connections, MIN(time) AS first_seen FROM hb_network_connection WHERE (instr(',' || '{{meeting_domains}}' || ',', ',' || LOWER(dst_endpoint_hostname) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, dst_endpoint_hostname, process_name ORDER BY connections DESC",
        "silence": "not_evidence_of_absence",
        "expected": "Connections from the Zimbra backend to Zoom, Teams, or Google Meet. Servers typically do not connect to these directly; users do from endpoints.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "triage-agent",
      "type": "analytic",
      "label": "Triage manipulation evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network"
        ],
        "context": [
          "identify-zimbra-servers",
          "forwarding-prevalence",
          "meeting-connections"
        ],
        "objective": "Determine if the Zimbra host shows evidence of unauthorized administrative modification and whether those changes coincide with server-initiated meeting platform connections.",
        "description": "Correlate administrative commands and network connections to identify compromised Zimbra hosts.",
        "max_iterations": 6,
        "expected_signal": "A per-host verdict citing specific filter changes and meeting platform interactions.",
        "success_criteria": "A per-host verdict of malicious, suspicious, or benign, citing the rows from the process and network surfaces."
      },
      "parents": [
        {
          "id": "forwarding-prevalence",
          "kind": "merge"
        },
        {
          "id": "meeting-connections",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on manipulation verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict is malicious for at least one Zimbra host, indicating filter manipulation or calendar warfare",
        "condition": "the triage verdict is malicious for at least one Zimbra host, indicating filter manipulation or calendar warfare",
        "blind_spot": "app-internal-manipulation",
        "confidence": "high",
        "description": "Route the investigation based on the agent verdict.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-agent"
        }
      ]
    },
    {
      "id": "isolate-compromised-host",
      "type": "action",
      "label": "Isolate compromised Zimbra server",
      "config": {
        "target": "endpoint",
        "description": "Stop the attacker from further manipulating the communication environment.",
        "instructions": "Isolate the Zimbra server immediately. Revoke and reset all administrative credentials and the Zimbra service account credentials.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "manual-artifact-review",
      "type": "task",
      "label": "Forensic mailbox and drive audit",
      "config": {
        "assignee": "analyst",
        "description": "Review application-level artifacts to confirm the extent of the BEC manipulation.",
        "instructions": "Log into the Zimbra administrative console. Audit mailbox forwarding for Finance and HR users. Review shared enterprise drives for HR memos or financial summaries updated within the lookback window. Cross-reference meeting invites containing Zoom links with the network connections identified in the hunt."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-compromised-host"
        }
      ]
    },
    {
      "id": "final-close-out",
      "type": "task",
      "label": "Final close out",
      "config": {
        "assignee": "analyst",
        "description": "Record the hunt outcome and any gaps in visibility.",
        "instructions": "Record the baseline of administrative activity. Document that application-internal changes like RSVP flipping or Sent Items deletion remained invisible to endpoint surfaces."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "manual-artifact-review"
        }
      ]
    }
  ]
}