// Zimbra
Zimbra Zero-Day, AI-Ranked RATs, and Trojanized Apps: July 24 Threat Briefing
By NeoShield AI Threat Desk · Published 2026-07-24 · 5 min read
#Zimbra#zero-day#Russian APT#Laundry Bear#Void Blizzard#SectopRAT#DolphinX#RAT
A Russian espionage group's exploitation of a Zimbra zero-day headlines a day packed with credential theft, AI-assisted targeting, and supply-chain-style malware delivery. Here is what defenders need to prioritize right now.
The most urgent story of the day centers on Zimbra Collaboration. A Russian state-sponsored group, publicly attributed to Laundry Bear (also tracked as Void Blizzard), exploited a zero-click vulnerability in Zimbra's webmail client for months before the flaw was patched. The payload was surgical: it harvested up to 90 days of email content, the full organizational address book, browser-saved passwords, and two-factor authentication codes. CISA has issued a warning confirming active exploitation and urging immediate patching. The zero-click nature of this flaw is particularly alarming — victims did not need to click anything for the compromise to succeed. Any organization running Zimbra Collaboration that has not applied the relevant patch is effectively operating with an open door to a nation-state actor.
Running in parallel, a new remote access trojan called Dolphin X has surfaced with a capability that deserves serious attention from threat intelligence teams. The malware claims to incorporate an AI-powered profiling engine that scores and ranks infected hosts, helping operators identify which victims are worth escalating attention toward. While the underlying AI mechanism should be treated with healthy skepticism until independently verified, the behavioral implication is clear: defenders can no longer assume that a low-profile endpoint is safe from follow-on activity simply because it does not appear valuable at first glance. Dolphin X represents a shift toward automated triage on the attacker side, compressing the window between initial access and targeted exploitation.
On the malvertising front, a campaign running through Bing search ads is delivering SectopRAT by impersonating the Claude AI desktop application. The lure is convincing enough that the fake installer was hosted on infrastructure mimicking the legitimate Claude.ai domain. SectopRAT is a well-documented information stealer and remote access tool capable of capturing browser data, credentials, and screen content. This campaign is a direct threat to any employee who searches for AI productivity tools and downloads software without verifying the source — a behavior that has become extremely common as AI application adoption accelerates across enterprises.
Ukraine's CERT has separately documented attacks abusing Notepad++, a widely trusted text editor, by distributing a malicious archive that bundles the legitimate application with a plugin called LunchPoke. The plugin establishes persistence quietly, exploiting the trust users and security tools extend to a well-known application. This is a classic living-off-the-land adjacent technique: use a trusted binary as cover for malicious functionality. Finally, Australian energy provider Origin Energy has confirmed a data breach exposing customer PII, a reminder that third-party and supply-chain data exposure continues to affect critical infrastructure sectors.
Defensive priorities for July 24:
- Zimbra patching is non-negotiable. Identify all Zimbra Collaboration instances in your environment immediately and confirm the patch addressing the zero-click webmail vulnerability is applied. If patching cannot happen within 24 hours, consider restricting external access to the webmail interface until it can.
- Audit browser-saved credentials across your organization. The Zimbra payload specifically targeted passwords stored in browsers. Enforce enterprise password manager policies and disable browser-native credential storage where possible via group policy or endpoint management tooling.
- Review 2FA token handling. TOTP codes harvested from a compromised session are time-limited but dangerous. Consider hardware security keys (FIDO2/passkeys) as a more phishing and theft-resistant alternative for high-value accounts.
- Block and monitor for Dolphin X indicators. Work with your threat intelligence feeds to obtain current indicators of compromise for Dolphin X. Pay particular attention to unusual outbound connections from endpoints that may not appear high-value — the malware's AI ranking means any infected host could become a priority target.
- Enforce application allowlisting and verify AI tool downloads. The fake Claude campaign exploits the rush to adopt AI tools. Publish an approved list of sanctioned AI applications, block unsigned or unverified installers at the endpoint, and consider DNS filtering to block lookalike domains.
- Audit Notepad++ plugin directories. If Notepad++ is present in your environment, verify that only known, legitimate plugins exist in the plugin directory. Unexpected DLLs or executables in that path should be treated as suspicious and investigated.
- Treat the Origin Energy breach as a credential hygiene trigger. If any employees or customers share credentials across services, now is the time to enforce password resets and check for credential exposure via your threat intelligence platform.
The convergence of a nation-state zero-day, AI-assisted malware triage, and trojanized trusted tools in a single news cycle underscores that the threat landscape is not slowing down. Defenders who prioritize patching, credential hygiene, and verified software sourcing will be best positioned to weather this wave.
This briefing is informational only and does not replace official vendor advisories or guidance from CISA and relevant national CERTs.
Related articles
Lazarus Zero-Day, Patch Tuesday Avalanche, and Portal Data Theft: August 13 Threat Briefing
A North Korean zero-day targeting defense firms headlines a massive Microsoft Patch Tuesday while CISA flags three actively…
Patch TuesdayPatch Tuesday Avalanche & Cisco Firewall Crisis: What Security Teams Must Do Now
Microsoft's August 2026 Patch Tuesday drops fixes for nearly 400 vulnerabilities including an actively exploited Windows kernel…
Zero-daySupply Chains, Zero-Days, and Backdoors: August 11 Threat Roundup for Defenders
This week's threat landscape is defined by trust exploitation — from trojanized software installers and unauthenticated admin…
NeoShield Security publishes defensive cybersecurity guides for developers, small teams, SOC learners, and MSPs. AI-assisted content is reviewed for safety, defensive purpose, and practical security value.