APT / THREAT GROUP

ZimReaper

2
aliases
Last seen:Jul 26, 2026

Intelligence Profile

According to Proofpoint, ZimReaper is a JavaScript-based malware family delivered via a half-click cross-site scripting exploit (CVE-2025-66376) targeting Zimbra Collaboration Suite webmail servers, requiring only that the victim open or preview a malicious email in the webmail client. The exploit uses a tag-splitting technique where CSS "@import" directives fragment HTML tags to bypass Zimbra's client-side HTML sanitizer, allowing arbitrary JavaScript execution in the context of the authenticated webmail session. Once executed, ZimReaper steals the CSRF token, auto-filled credentials, and two-factor authentication codes from the browser, creates an app-specific password named "ZimbraWeb" for persistent IMAP/POP3/SMTP access, and exfiltrates stolen data via DNS queries and HTTP POST. The malware also enumerates the Global Address List and exfiltrates the last 90 days of the victim's emails in a TGZ archive, using obfuscation layers including XOR-encrypted payloads that evolved over the course of the campaign.

Threat Analysis

ZimReaper is a known-sophistication threat actor of undetermined national origin, engaged in cyber operations with a primary motivation of unknown activity patterns.

External References

Quick Facts

TypeAPT / Threat Group
Aliases2

Also Known As

ZimReaperjs.zimreaper

External Intelligence

Malpedia: js.zimreaper

Research Links

Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.