Summary:
Researchers has observed new espionage campaign run by Russian Threat Actor TAG-70 leveraging cross-site scripting (XSS) vulnerabilities against Roundcube webmail servers in Europe, targeting government, military, and national infrastructure-related entities. The group likely conducts cyber-espionage campaigns to serve the interests of Belarus and Russia and has been active since at least December 2020, primarily targeting governments sector in Europe and Central Asia. In their latest campaign, TAG-70 likely started exploiting Roundcube webmail servers at the beginning of October 2023 and continued until at least mid-October. Research team has detected at least 80 organizations targeted in this campaign; the victims were primarily entities in Georgia, Poland, and Ukraine. This campaign has been linked to additional TAG-70 activity against Uzbekistan government mail servers, which involved infrastructure reported by another research group in February 2023.[/subscribe_to_unlock_form]
Summary:
Researchers has observed new espionage campaign run by Russian Threat Actor TAG-70 leveraging cross-site scripting (XSS) vulnerabilities against Roundcube webmail servers in Europe, targeting government, military, and national infrastructure-related entities. The group likely conducts cyber-espionage campaigns to serve the interests of Belarus and Russia and has been active since at least December 2020, primarily targeting governments sector in Europe and Central Asia. In their latest campaign, TAG-70 likely started exploiting Roundcube webmail servers at the beginning of October 2023 and continued until at least mid-October. Research team has detected at least 80 organizations targeted in this campaign; the victims were primarily entities in Georgia, Poland, and Ukraine. This campaign has been linked to additional TAG-70 activity against Uzbekistan government mail servers, which involved infrastructure reported by another research group in February 2023.[emaillocker id="1283"]
The campaign, detected by research group involves the exploitation of Roundcube webmail servers using JavaScript-based malware. The malware utilizes a second-stage loader loaded via cross-site scripting (XSS) from malicious emails. This loader decodes a Base64-encoded payload and inserts it into the Document Object Model (DOM) of the Roundcube webpage, effectively compromising the victim's email credentials. Furthermore, the analysis uncovers the infrastructure used by TAG-70 to arrange its operations. The group employs a network of C2 servers, often obfuscated through Tor, to relay data from compromised endpoints. Suspicious activities were detected, linking victim IP addresses to known C2 domains like bugiplaysec[.]com and ocsp-reloads[.]com. TAG-70's infrastructure includes domains like hitsbitsx[.]com and recsecas[.]com, which have been observed with dynamic IP address changes, indicating an effort to evade detection and maintain operational resilience.
To mitigate the threat posed by TAG-70 and similar adversaries, organizations are advised to strengthen email security measures, conduct regular security audits, and prioritize employee awareness training. Network segmentation, collaboration with security vendors and intelligence agencies, and the development of robust incident response plans are also recommended strategies to enhance defense posture against sophisticated cyber threats.
Threat Profile:

References:
The following reports contain further technical details:
https://thehackernews.com/2024/02/russian-linked-hackers-breach-80.html
[/emaillocker]