+38 067 569 61 50

info@clapkey.com

Cyber threat: Volodymyr Zelenskyy presented the Golden Star Orders to servicemen of the Armed Forces of Ukraine and members of the families of the fallen Heroes of Ukraine

Cyber threat: Volodymyr Zelenskyy presented the Golden Star Orders to servicemen of the Armed Forces of Ukraine and members of the families of the fallen Heroes of Ukraine

An email with the subject "Volodymyr Zelenskyy presented the Golden Star Orders to servicemen of the Armed Forces of Ukraine and members of the families of the fallen Heroes of Ukraine" and several images is circulating online.

The investigation found that the email header "Content-Location" contains JavaScript code whose execution leads to the download and execution of another JavaScript code, intended to add a third-party email address to the victim's email account configuration in order to subsequently forward the user's emails to it.

The technical possibility of implementing the described threat is classified under identifier CVE-2018-6882 as an XSS (Cross-Site Scripting) vulnerability in Zimbra Collaboration Suite (< 8.7 Patch 1, 8.8.x < 8.8.7).

Given the subject, content, attachments and recipients of the email, the detected activity is targeted and will be tracked under the identifier UAC-0097.

Indicators of compromise:

Files:

ddeab2d94128abbf9b4bf8ade4f9919e ad75a9a8eb1210d04873c151ada56520d582cc1012a50895d6c06bb60160d6b8 junit.js

Network:

joey@kmtacn[.]com (X-FE-Envelope-From) 211.234.110[.]194 (X-FE-Last-Public-Client-IP) hxxps://cdn.jsdelivr[.]net/gh/sukaut/beta@main/junit.js repo.ma@hotmail[.]com (email address used for exfiltration) nov.td@yandex[.]ru (related email address) hxxps://github[.]com/sukaut (corresponding GitHub repository)

Recommendations:

1. Ensure timely updates of the Zimbra software.

2. Ensure secure configuration of the Zimbra software in line with best practices (hxxps://wiki.zimbra[.]com/wiki/SecureConfiguration).

3. Take measures to check for settings related to filters and/or email forwarding (used as a means of data exfiltration).

You can also email us at sd@clapkey.com and we will help you with updates and an IT audit

Vulnerability information from cert.gov.ua

This page has been translated partially or fully using AI. Please send any translation feedback to info@clapkey.com.

#StandWithUkraine

Support the Armed Forces of Ukraine during the russian invasion

Contacts

Office

4th floor, Metropoliten Shopping Center (38 Gogolya St.), Poltava, Ukraine, 36000