EXECUTIVE SUMMARY
Operation RoundPress is a cyberespionage campaign targeting vulnerable webmail platforms through carefully crafted spearphishing emails exploiting cross-site scripting flaws. The operation centers on injecting malicious JavaScript into webmail portals, enabling credential theft and data exfiltration from specific mailboxes. Initially limited to Roundcube, the campaign later expanded to include Horde, MDaemon, and Zimbra. The campaign has primarily focused on defense-related entities and government institutions across Eastern Europe, with additional activity noted in Africa, Europe, and South America. Attackers used previously patched vulnerabilities in some cases and a zero-day XSS flaw in MDaemon in others, highlighting the group’s ability to discover and weaponize new exploits. These phishing emails were disguised as legitimate messages about local and geopolitical news, making them appear trustworthy to targets who opened them through vulnerable webmail platforms.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
Operation RoundPress is a cyberespionage campaign targeting vulnerable webmail platforms through carefully crafted spearphishing emails exploiting cross-site scripting flaws. The operation centers on injecting malicious JavaScript into webmail portals, enabling credential theft and data exfiltration from specific mailboxes. Initially limited to Roundcube, the campaign later expanded to include Horde, MDaemon, and Zimbra. The campaign has primarily focused on defense-related entities and government institutions across Eastern Europe, with additional activity noted in Africa, Europe, and South America. Attackers used previously patched vulnerabilities in some cases and a zero-day XSS flaw in MDaemon in others, highlighting the group’s ability to discover and weaponize new exploits. These phishing emails were disguised as legitimate messages about local and geopolitical news, making them appear trustworthy to targets who opened them through vulnerable webmail platforms.[emaillocker id="1283"]
The execution of Operation RoundPress involves multiple variants of JavaScript payloads tailored to the webmail platform exploited. SpyPress.ROUNDCUBE, SpyPress.HORDE, SpyPress.MDAEMON, and SpyPress.ZIMBRA share a similar structure, aiming to capture credentials, steal email messages, and exfiltrate contacts. Some variants exhibit additional features—SpyPress.MDAEMON includes functionality to bypass two-factor authentication, while SpyPress.ROUNDCUBE can create persistent Sieve rules to forward incoming emails to attacker-controlled inboxes. These payloads are stealthily embedded in the body of the phishing emails and triggered upon viewing. Each script is obfuscated, with encrypted strings and randomized variable names, complicating analysis, and signature-based detection.
Attribution links Operation RoundPress to a known cyberespionage group with a history of targeting geopolitical adversaries and using tailored malware. Indicators such as email account reuse and infrastructure configuration patterns match previous campaigns associated with this actor. Domains and IP addresses used in RoundPress share distinct traits with infrastructure used in earlier operations tied to the same entity. Furthermore, phishing messages sent from email addresses stylistically like those seen in prior campaigns reinforce this connection. The tactics used—including the use of XSS exploits in webmail software and the development of specialized scripts to extract inbox data—are consistent with the group’s previous activity. Collectively, these technical and infrastructural similarities support the conclusion that RoundPress is a continuation of long-running efforts by this group to surveil high-value diplomatic, governmental, and military targets.
THREAT PROFILE:
| Tactics | Technique ID | Technique |
| Resource Development | T1583 | Acquire Infrastructure |
| T1587 | Develop Capabilities | |
| Initial Access | T1190 | Exploit Public-Facing Application |
| Execution | T1203 | Exploitation for Client Execution |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| Credential Access | T1187 | Forced Authentication |
| T1556 | Modify Authentication Process | |
| Discovery | T1087 | Account Discovery |
| Collection | T1056 | Input Capture |
| T1119 | Automated Collection | |
| T1114 | Email Collection | |
| Command and Control | T1071 | Application Layer Protocol |
| T1132 | Data Encoding | |
| Exfiltration | T1020 | Automated Exfiltration |
| T1041 | Exfiltration Over C2 Channel |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]