Disclaimer: The URLs and access methods described refer to a protected government system. Unauthorized access is a violation of Ukrainian and international cyber laws.

(ongoing): Since late 2024, some police and government entities have moved to either Microsoft 365 Government (cloud) or the E-mail System of the State (internal developed solution). However, many legacy Zimbra servers remain operational.

These attacks typically manifest in two ways:

Based on similar campaigns targeting the .gov.ua sector, the "zimbra police gov ua" activity likely involves:

(Zimbra RCE via Memcached injection)