攻击者在 Zimbra 邮件服务器的一个关键漏洞被公开披露数周前,就一直在对其进行探测,随后转而窃取凭据、入侵邮箱,并对受感染的系统进行更深入的控制。
Attackers were poking at a critical Zimbra mail server bug weeks before it was publicly disclosed, and then moved on to steal credentials, raid mailboxes, and take deeper control of compromised systems.
微软威胁情报中心(Microsoft Threat Intelligence)表示,其追踪了针对 CVE-2026-73570 的利用活动。这是 Zimbra 协作套件(Zimbra Collaboration Suite)中的一个无需身份验证的命令注入漏洞,攻击者可借此轻松入侵暴露在外的邮件服务器。
Microsoft Threat Intelligence said it tracked exploitation of CVE-2026-73570, an unauthenticated command injection vulnerability in Zimbra Collaboration Suite that gives attackers a potentially easy route into exposed mail servers.
此攻击既不需要窃取密码,也不需要不幸的员工点击可疑链接。攻击者只需向易受攻击的面向互联网的服务器发送一封精心构造的电子邮件,就有可能运行命令,不过微软总部(Redmond)指出,该漏洞仅影响运行 Zimbra 可选 SNMP 监控包且启用了通知功能的服务器。
No stolen password or unfortunate employee clicking a dodgy link is required. An attacker can send a specially crafted email to a vulnerable internet-facing server and potentially run commands, though Redmond notes the flaw affects only servers running Zimbra's optional SNMP monitoring package with notifications enabled.
Zimbra 于 7 月 20 日在 1.1.20 版本中修复了该漏洞,但 CVE-2026-73570 直到 8 月 13 日才被公开披露。
Zimbra fixed the flaw in version 10.1.20 on July 20, but CVE-2026-73570 wasn't publicly disclosed until August 13.
在 7 月 28 日至 8 月 7 日期间,微软总部发现两个不同的扫描工具正在探测 Zimbra 随后在攻击中被利用的同一部分。起初,这些活动似乎主要集中在寻找易受攻击的服务器和测试该漏洞上。
Between July 28 and August 7, Redmond spotted two different scanning tools probing the same part of Zimbra later used in attacks. At first, the activity appears to have focused on finding vulnerable servers and testing the flaw.
攻击者使用了一系列常见的网络实用工具,使易受攻击的系统回连到他们控制的基础设施上,从而确认他们可以执行命令。
The attackers used a collection of common network utilities to make vulnerable systems call back to infrastructure they controlled, confirming they could execute commands.
一旦他们找到了配合的服务器,情况就变得更加复杂了。微软的调查发现,攻击者部署了 Web shell 和反向 shell,提升了权限,安装了用于持久化远程访问的工具,并直接在内存中运行恶意代码。
Once they found servers that played ball, things got messier. Microsoft's investigation found attackers deploying web shells and reverse shells, escalating their privileges, installing tools for persistent remote access, and running malicious code directly in memory.
有些攻击者甚至在事后清理痕迹。微软表示,攻击者曾临时更改公共目录的权限以植入 Web shell,随后又恢复了原始设置,这显然是企图让他们的干预行为更难被发现。
Some even tidied up after themselves. Microsoft said attackers temporarily changed permissions on public directories to plant web shells, then restored the original settings afterward in an apparent attempt to make their meddling harder to spot.
入侵者还探索了他们所处的更广泛的 Zimbra 环境,识别其他邮件服务器,并寻找可用于在服务器之间横向移动的信任连接。
The intruders also explored the wider Zimbra environments they landed in, identifying other mail servers and looking for trusted connections they could use to move between them.
在某些情况下,Zimbra系统之间已存在的SSH连接为攻击者提供了通往邻近服务器的途径。在至少一台被入侵的机器上,攻击者成功获得了root权限;随后他们设置了相应的机制,使得自己能够无需密码即可继续以最高权限执行命令。邮箱自然也成为攻击者的目标。微软表示,攻击者专门寻找可用于访问用户账户的Zimbra凭证和认证信息。
In some cases, existing SSH relationships between Zimbra systems gave them a route to neighboring servers. On at least one compromised machine, attackers turned their initial foothold into root access. They then set things up to keep running commands with the highest privileges without needing a password. Mailboxes were, unsurprisingly, also on the shopping list. Microsoft said attackers hunted for Zimbra credentials and authentication secrets that could potentially be used to access user accounts.
其中一种恶意工具专门用于提取服务账户的凭证,并从Zimbra的数据库中获取邮箱信息。在另一起事件中,攻击者将最新的邮箱备份文件打包成压缩文件,试图利用微软自带的AzCopy工具将这些数据传输到Azure Blob存储服务中;不过微软无法根据现有证据确认该传输操作是否真的成功完成。受影响的组织遍布多个地区和行业,攻击手段从自动化攻击到需要人工操作的复杂攻击行为都有。
One malicious tool it uncovered was built specifically to extract service account credentials and pull mailbox information from Zimbra's databases. In another incident, attackers bundled recent mailbox backups into an archive and tried to ship the haul to Azure Blob Storage using Microsoft's own AzCopy utility. Microsoft said it couldn't confirm from the evidence available whether the transfer actually succeeded. The company saw affected organizations across multiple regions and industries, with the attacks ranging from automated exploitation to more deliberate hands-on-keyboard activity.
微软尚未确定这些攻击行为的幕后黑手。使用Zimbra 10.1.20之前版本的管理者应尽快将系统升级至10.1.20或更高版本;如果无法进行升级,可以通过移除可选的SNMP组件或禁用SNMP通知功能来降低系统风险。值得注意的是,攻击者似乎很早就发现了该安全漏洞——微软在漏洞公开披露前两周就发现了相关探测行为。
It hasn't attributed the activity to a particular crew. Admins running versions earlier than Zimbra 10.1.20 should update to 10.1.20 or later, while those unable to patch can reduce their exposure by removing the optional SNMP package or disabling SNMP notifications. Attackers, meanwhile, appear to have gotten there early, with Microsoft spotting probes for the flaw more than two weeks before it was publicly disclosed. ®