Threat Advisory

Operation RoundPress Targets Webmail Servers via XSS Flaws

Threat: Malicious Campaign
Threat Actor Name: APT28
Threat Actor Type: State-Sponsored
Targeted Region: Africa, Europe, South America, Ukraine
Alias: G0007,Fancy Bear, Strontium/Forest Blizzard, Sofacy, Fighting Ursa, TA422, Swallowtail, BlueDelta , TAG-0700, ITG05, Iron Twilight, Pawn Storm, UAC-0028/UAC-0063, Blue Athena, ATK5, TG-4127 , APT-C-20 , T-APT-12 , Group74 , Sednit , Tsar Team , Grizzly Steppe , Snakemackerel, The Dukes , SIG40 , Frozenlake
Threat Actor Region: Russia
Targeted Sector: Technology & IT, Government & Defense
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Operation RoundPress is a cyberespionage campaign targeting vulnerable webmail platforms through carefully crafted spearphishing emails exploiting cross-site scripting flaws. The operation centers on injecting malicious JavaScript into webmail portals, enabling credential theft and data exfiltration from specific mailboxes. Initially limited to Roundcube, the campaign later expanded to include Horde, MDaemon, and Zimbra. The campaign has primarily focused on defense-related entities and government institutions across Eastern Europe, with additional activity noted in Africa, Europe, and South America. Attackers used previously patched vulnerabilities in some cases and a zero-day XSS flaw in MDaemon in others, highlighting the group’s ability to discover and weaponize new exploits. These phishing emails were disguised as legitimate messages about local and geopolitical news, making them appear trustworthy to targets who opened them through vulnerable webmail platforms.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Operation RoundPress is a cyberespionage campaign targeting vulnerable webmail platforms through carefully crafted spearphishing emails exploiting cross-site scripting flaws. The operation centers on injecting malicious JavaScript into webmail portals, enabling credential theft and data exfiltration from specific mailboxes. Initially limited to Roundcube, the campaign later expanded to include Horde, MDaemon, and Zimbra. The campaign has primarily focused on defense-related entities and government institutions across Eastern Europe, with additional activity noted in Africa, Europe, and South America. Attackers used previously patched vulnerabilities in some cases and a zero-day XSS flaw in MDaemon in others, highlighting the group’s ability to discover and weaponize new exploits. These phishing emails were disguised as legitimate messages about local and geopolitical news, making them appear trustworthy to targets who opened them through vulnerable webmail platforms.[emaillocker id="1283"]

The execution of Operation RoundPress involves multiple variants of JavaScript payloads tailored to the webmail platform exploited. SpyPress.ROUNDCUBE, SpyPress.HORDE, SpyPress.MDAEMON, and SpyPress.ZIMBRA share a similar structure, aiming to capture credentials, steal email messages, and exfiltrate contacts. Some variants exhibit additional features—SpyPress.MDAEMON includes functionality to bypass two-factor authentication, while SpyPress.ROUNDCUBE can create persistent Sieve rules to forward incoming emails to attacker-controlled inboxes. These payloads are stealthily embedded in the body of the phishing emails and triggered upon viewing. Each script is obfuscated, with encrypted strings and randomized variable names, complicating analysis, and signature-based detection.

Attribution links Operation RoundPress to a known cyberespionage group with a history of targeting geopolitical adversaries and using tailored malware. Indicators such as email account reuse and infrastructure configuration patterns match previous campaigns associated with this actor. Domains and IP addresses used in RoundPress share distinct traits with infrastructure used in earlier operations tied to the same entity. Furthermore, phishing messages sent from email addresses stylistically like those seen in prior campaigns reinforce this connection. The tactics used—including the use of XSS exploits in webmail software and the development of specialized scripts to extract inbox data—are consistent with the group’s previous activity. Collectively, these technical and infrastructural similarities support the conclusion that RoundPress is a continuation of long-running efforts by this group to surveil high-value diplomatic, governmental, and military targets.

THREAT PROFILE:

Tactics Technique ID Technique
Resource Development T1583 Acquire Infrastructure
T1587 Develop Capabilities
Initial Access T1190 Exploit Public-Facing Application
Execution T1203 Exploitation for Client Execution
Defense Evasion T1027 Obfuscated Files or Information
Credential Access T1187 Forced Authentication
T1556 Modify Authentication Process
Discovery T1087 Account Discovery
Collection T1056 Input Capture
T1119 Automated Collection
T1114 Email Collection
Command and Control T1071 Application Layer Protocol
T1132 Data Encoding
Exfiltration T1020 Automated Exfiltration
T1041 Exfiltration Over C2 Channel

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu