CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

ELock

malware · malware:elock

Ransomware family that Italy's national CSIRT (ACN) found in two cases on internet-exposed Zimbra servers, one reached through the SNMP command injection CVE-2026-73570 and one through an older flaw; ACN describes it as known to target enterprise environments and Zimbra Collaboration Suite installations (ACN / CSIRT Italia, 2026-10-05).

Aliases: ELock ransomware

Coverage
1
first 2026-08-20 → last 2026-10-06
Latest activity
2026-10-06
Fixed on 20 July, identified on 13 August, probed from 28 July: a CVE-keyed patch process never saw this one…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, education, telco · regions: europe
Sources cited
10
8 hosts

Action items (2)

Do-now tasks recorded on the entries about ELock, newest first. Check the date before acting on an older one.

  • Upgrade every Zimbra Collaboration host to 10.1.21 (10.1.20 is the minimum for CVE-2026-73570); where the upgrade cannot happen at once, remove the zimbra-snmp package or disable SNMP notifications and restrict SNMP and SMTP to trusted hosts.
    2026-08-20CVE-2026-73570
  • On every host that ran a build before 10.1.20 with SNMP notifications enabled at any time since 2026-07-28, upgrading is not enough: rotate all domain zimbraPreAuthKey values and run the compromise check on every mailbox node, covering the zimbra user's crontab and /opt/zimbra/.ssh/authorized_keys, JSP or stray text files under /opt/zimbra/jetty_base/webapps/zimbra/public, droppers in /tmp and /var/tmp, and outbound connections from the mail server; where web shells or an LDAP dump turn up, rotate every mailbox and administrative credential.
    2026-08-20CVE-2026-73570

Defender insights

What each entry about ELock tells a defender to do, newest first.

2026-08-20HIGHexploitedFixed on 20 July, identified on 13 August, probed from 28 July: a CVE-keyed patch process never saw this one coming

Exposure · triage · detection

Story timeline

  1. 2026-08-20CVE-2026-73570, Zimbra Collaboration: a pre-auth command injection patched without a CVE in July is exploited, with probing before disclosure and root escalation, secret theft and cluster-wide movement observed
    trending-vulnerabilitiesFixed on 20 July, identified on 13 August, probed from 28 July: a CVE-keyed patch process never saw this one coming
ATT&CK techniques (23 across 11 tactics)

23 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • ReconnaissanceActive Scanning: Vulnerability Scanning
  • Initial AccessExploit Public-Facing Application
  • ExecutionScheduled Task/Job: Cron · Command and Scripting Interpreter: Unix Shell
  • PersistenceScheduled Task/Job: Cron · Server Software Component: Web Shell · Create or Modify System Process: Systemd Service
  • Privilege EscalationScheduled Task/Job: Cron · Create or Modify System Process: Systemd Service · Abuse Elevation Control Mechanism: Sudo and Sudo Caching
  • StealthMasquerading: Match Legitimate Resource Name or Location · Indicator Removal: Timestomp · Reflective Code Loading
  • Credential AccessBrute Force · Unsecured Credentials: Credentials In Files
  • Lateral MovementRemote Services: SSH · Lateral Tool Transfer
  • CollectionData from Local System · Email Collection: Local Email Collection · Archive Collected Data: Archive via Utility
  • Command and ControlApplication Layer Protocol: Web Protocols · Proxy · Ingress Tool Transfer
  • ImpactData Encrypted for Impact · Resource Hijacking: Compute Hijacking · Account Access Removal

Reconnaissance TA0043

T1595.002Active Scanning: Vulnerability Scanning×1

Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use.

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

Execution TA0002

T1053.003Scheduled Task/Job: Cron×1

Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

T1059.004Command and Scripting Interpreter: Unix Shell×1

Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

Persistence TA0003

T1053.003Scheduled Task/Job: Cron×1

Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

T1543.002Create or Modify System Process: Systemd Service×1

Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon processes (also known as services) and other system resources. Systemd is the default initialization (init) system on many Linux distributions replacing legacy init systems, including SysVinit and Upstart, while remaining backwards compatible.

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

Privilege Escalation TA0004

T1053.003Scheduled Task/Job: Cron×1

Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

T1543.002Create or Modify System Process: Systemd Service×1

Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon processes (also known as services) and other system resources. Systemd is the default initialization (init) system on many Linux distributions replacing legacy init systems, including SysVinit and Upstart, while remaining backwards compatible.

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

T1548.003Abuse Elevation Control Mechanism: Sudo and Sudo Caching×1

Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges. Adversaries may do this to execute commands as other users or spawn processes with higher privileges.

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

Stealth TA0005

T1036.005Masquerading: Match Legitimate Resource Name or Location×1

Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

T1070.006Indicator Removal: Timestomp×1

Adversaries may modify file time attributes to hide new files or changes to existing files. Timestomping is a technique that modifies the timestamps of a file (the modify, access, create, and change times), often to mimic files that are in the same folder and blend malicious files with legitimate files.

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

T1620Reflective Code Loading×1

Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules).

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

Credential Access TA0006

T1110Brute Force×1

Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained. Without knowledge of the password for an account or set of accounts, an adversary may systematically guess the password using a repetitive or iterative mechanism. Brute forcing passwords can take place via interaction with a service that will check the validity of those credentials or offline against previously acquired credential data, such as password hashes.

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

T1552.001Unsecured Credentials: Credentials In Files×1

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

Lateral Movement TA0008

T1021.004Remote Services: SSH×1

Adversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH). The adversary may then perform actions as the logged-on user.

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

T1570Lateral Tool Transfer×1

Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., Ingress Tool Transfer) files may then be copied from one system to another to stage adversary tools or other files over the course of an operation.

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

Collection TA0009

T1005Data from Local System×1

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

T1114.001Email Collection: Local Email Collection×1

Adversaries may target user email on local systems to collect sensitive information. Files containing email data can be acquired from a user’s local system, such as Outlook storage or cache files.

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

T1560.001Archive Collected Data: Archive via Utility×1

Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities include functionalities to compress, encrypt, or otherwise package data into a format that is easier/more secure to transport.

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

Command and Control TA0011

T1071.001Application Layer Protocol: Web Protocols×1

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

T1090Proxy×1

Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

T1105Ingress Tool Transfer×1

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

Impact TA0040

T1486Data Encrypted for Impact×1

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

T1496.001Resource Hijacking: Compute Hijacking×1

Adversaries may leverage the compute resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

T1531Account Access Removal×1

Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts. Adversaries may also subsequently log off and/or perform a System Shutdown/Reboot to set malicious changes into place.

Evidence: 2026-08-20/cve-2026-73570-zimbra-snmp-command-injection-exploited · ATT&CK page ↗

Entries about ELock (1)

2026-08-20 · view entry permalink →

HIGHCVE-2026-73570exploitedupdatedNATOA1

CVE-2026-73570, Zimbra Collaboration: a pre-auth command injection patched without a CVE in July is exploited, with probing before disclosure and root escalation, secret theft and cluster-wide movement observed

Zimbra's own security-advisory table records the fix for CVE-2026-73570 as "Fixed a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled", shipped in release 10.1.20 (Zimbra, 2026-08-13). That release went out on 20 July 2026 (Zimbra, 2026-07-20) carrying nine fixes, and at the time none of them had been flagged as actively exploited; the vendor's stated position was that "in line with industry best practices, information disclosure is limited for security vulnerability fixes" (The Hacker News, 2026-07-21). The identifier arrived 24 days later, on 13 August, and the ENISA record describes the mechanism in full: because untrusted input is not properly sanitised during SNMP notification processing, "an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user" (ENISA EU Vulnerability Database, 2026-08-13). ENISA scores it 8.9 with high attack complexity (ENISA EU Vulnerability Database, 2026-08-13), and the flaw applies only to deployments where the optional zimbra-snmp package is installed and SNMP notifications are enabled.

On 19 August CERT-FR issued its own advisory for the Zimbra bulletin and stated plainly that ENISA records CVE-2026-73570 as actively exploited (CERT-FR, 2026-08-19). ENISA's record lists it in the EU KEV catalog from 18 August (ENISA EU Vulnerability Database, 2026-08-13). What makes this worth an out-of-band look rather than a place in the next patch window is the sequence rather than the score: the code was fixed in July with no identifier attached, so an estate that drives its patching from CVE feeds, scanner signatures or an SBOM pipeline had nothing to match against for 24 days, and the flaw only became visible to those processes five days before it was recorded as exploited. Anyone who upgraded to 10.1.20 in July for unrelated reasons is already covered and does not know it; anyone who deferred is now unpatched against a flaw with a published exploitation status.

ENISA indicates that vulnerability CVE-2026-73570 is being actively exploited. (translated from French)

CERT-FR (ANSSI) 2026-08-19

Fixed a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled.

Zimbra (vendor security advisories) 2026-08-13

none of the identified vulnerabilities have been flagged as actively exploited

The Hacker News 2026-07-21

Between July 28 and August 7, after a fix became available on July 20 but before public disclosure on August 13, Microsoft observed two distinct out-of-band scanning tools probing the vulnerable injection point.

Rotate all domain zimbraPreAuthKey values and review systemd units for unexpected ownership, enablement, or timestamp changes

Microsoft Threat Intelligence 2026-09-30

In two separate events, exploitation of CVE-2026-73570 culminated in the release of ransomware against the target servers. (translated from Italian)

No evidence emerged of successful intrusions against regularly updated instances. (translated from Italian)

ACN / CSIRT Italia
Updaterun 2026-10-02T0404Z-inteltitleheadlinesummarytagstechniquescvessourcesevidencesourcing_noteclassificationactionsupdate_ofbody

Microsoft Threat Intelligence published first-hand analysis on 2026-09-30 of CVE-2026-73570 exploitation in more than one region and industry, naming no actor (Microsoft Threat Intelligence, 2026-09-30). It saw two out-of-band scanning tools probing the injection point between 2026-07-28 and 2026-08-07, after the fix and before the 2026-08-13 disclosure (Microsoft Threat Intelligence, 2026-09-30). CISA's KEV catalog lists the CVE, added 2026-08-21 (CISA KEV, 2026-08-21).

After command execution as the zimbra account, Microsoft observed, across its cases and not necessarily on every host, JSP web shells written to publicly served directories after temporarily opening write permission, with copies on peer mailbox nodes, and reverse shells built from a named pipe and openssl s_client; a privilege escalation that used a symlinked log file to take ownership of the sudo PAM configuration, added a pam_exec hook and created a NOPASSWD sudoers entry for the zimbra account; a systemd unit named like a Zimbra logging component with timestamps matched to existing services; theft of Zimbra's service credentials with zmlocalconfig -s, followed by authenticated LDAP queries for the pre-authentication key, the auth-token key and the two-factor secret attribute; and SSH and rsync movement across the cluster with Zimbra's own SSH identity (Microsoft Threat Intelligence, 2026-09-30). Microsoft's remediation is to upgrade to 10.1.20 or later, remove the zimbra-snmp package or disable SNMP notifications and restrict SNMP and SMTP to trusted hosts, rotate all domain zimbraPreAuthKey values, review systemd units, and hunt for JSP files on every mailbox node (Microsoft Threat Intelligence, 2026-09-30).

Zimbra's 10.1.21 release of 2026-09-24 also fixes unauthenticated prediction of password-recovery codes that could reset a user's password, WebDAV acceptance of pre-MFA tokens, and OnlyOffice-integration flaws including file write to remote code execution (Zimbra, 2026-09-24); the table lists no CVE or score for the recovery-code and WebDAV fixes (Zimbra, 2026-08-13), and NCSC Switzerland published an advisory for the release on 2026-10-01 with exploitation status unknown (NCSC Switzerland, 2026-10-01).

Updaterun 2026-10-06T0405Z-intelsummarytagsentitiestechniquessourcesevidencesourcing_noteactionsbody

CSIRT Italia reports, in bulletin BL01/261005/CSIRT-ITA, multiple compromises of internet-exposed Zimbra servers handled in the Italian national context, mostly through CVE-2026-73570 and to a lesser extent through older flaws on unpatched or end-of-life instances (ACN / CSIRT Italia, 2026-10-05). In two CVE-2026-73570 cases exploitation ended in ransomware: on an 8.7.11 instance the attacker opened an interactive reverse shell and irreversibly encrypted many files on one node, and in a second case of unspecified version an ELock-family ransomware executable was dropped; both servers had the optional zimbra-snmp package, and the evidence does not tie the two cases to one actor or payload (ACN / CSIRT Italia, 2026-10-05). Three further cases installed cryptominers, one on 10.1.19 with a crontab entry for the zimbra user that ran a payload from a temporary directory (ACN / CSIRT Italia, 2026-10-05). In one case the exploit fetched a payload from external staging infrastructure and ran a Perl script directly in memory without writing files, with an attempted connection to a presumed IRC command-and-control server and no post-compromise activity found (ACN / CSIRT Italia, 2026-10-05). In two cases web shells were planted in the directories the web service exposes: on a 10.1.4 instance the attackers left JSP web shells, including ones managed with Behinder, and exfiltrated the LDAP database, the mailbox list and the credential hashes, and on another instance several JSP web shells took mail down for 48 hours for more than 6,000 mailboxes with no data theft documented (ACN / CSIRT Italia, 2026-10-05). The two cases share five command-and-control addresses and similar JSP constructs, but ACN says the evidence does not let it attribute both to the same actor (ACN / CSIRT Italia, 2026-10-05). ACN also describes a CentOS server turned into an SSH brute-force source after a write test in the Jetty public directory, with CVE-2026-73570 as the presumed but unconfirmed entry, and an end-of-life server whose mailbox passwords were all reset by the attacker through an undetermined vector (ACN / CSIRT Italia, 2026-10-05). Older flaws (CVE-2024-45519, CVE-2022-41352, CVE-2022-27925, CVE-2022-37042 and CVE-2023-38750) account for the remaining cases on unpatched or unsupported lines, including a further ransomware case on an 8.8.15 instance (ACN / CSIRT Italia, 2026-10-05).

ACN says nearly all affected systems lacked applicable patches or ran unsupported branches, that in several cases the attackers persisted without root by staying in the zimbra application user's context, and that it found no evidence of successful intrusions on regularly updated instances (ACN / CSIRT Italia, 2026-10-05). Its mitigations are to update, to disable or remove the zimbra-snmp package where patching has to wait, to inspect the zimbra user's crontab and /opt/zimbra/.ssh/authorized_keys, to look for SNMP exploit scripts under /opt/zimbra/data/tmp and for JSP files or stray text files in the Jetty public directory, to check /tmp and /var/tmp for droppers, miners and ransomware payloads, to rotate all mailbox and administrative credentials where web shells or anomalies are found, to keep the administrative port TCP 7071 and unneeded SOAP interfaces off the public internet, and to filter egress from the Zimbra servers, including IRC and TCP 8801 (ACN / CSIRT Italia, 2026-10-05).

vulnerability20 Aug 04:36Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • wiki.zimbra.com3 (30%)
  • acn.gov.it1 (10%)
  • cert.ssi.gouv.fr1 (10%)
  • cisa.gov1 (10%)
  • euvd.enisa.europa.eu1 (10%)
  • microsoft.com1 (10%)
  • security-hub.ncsc.admin.ch1 (10%)
  • thehackernews.com1 (10%)
All cited sources (10)