Are you saying Webmin was exposed to the public Internet? That alone provides a pretty broad attack surface...
If you also had Webmin open on your Desktop and went to another web site with an infected ad, that could also be the attack vector. See
Webmin for example.
If the root account on your Zimbra server has been compromised, just changing the root password is likely not sufficient for eliminating the exposure.
I'd strongly suggest engaging a professional security firm for an assessment.
Hope that helps,
Mark
__________________
___________________________________
L. Mark Stone, CIO
"Uptime. All the time."
477 Congress Street | Portland, ME 04101-3431 | (207) 772-5678
proactive maintenance and monitoring | technology consulting
Zimbra groupware | EMR implementations | private cloud hosting