Unidentified JS 007 (Zimbra Stealer)

Malware type
credential-stealer
Profile updated
2026-07-07 14:34:50

Targeted industries: technology-and-telecommunications

Context

According to Seqrite, this collector is delivered via a phishing mail and triggers via XSS in an active Zimbra session.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Js.Unidentified 007 (report)
  • seqrite.com — Operation Ghostmail Zimbra Xss Russian Apt Ukraine (report)

External references