Operation RoundPress is a cyberespionage campaign by the Sednit group targeting high-value webmail servers via XSS vulnerabilities to steal confidential email data. This operation affects multiple webmail platforms including Roundcube, Horde, MDaemon, and Zimbra, primarily impacting governmental and defense sectors worldwide. #Sednit #Roundcube #Horde #MDaemon #Zimbra
Keypoints
- Operation RoundPress uses spearphishing emails exploiting XSS vulnerabilities to inject malicious JavaScript into webmail pages.
- In 2023, the operation targeted only Roundcube, expanding in 2024 to Horde, MDaemon (zero-day CVE-2024-11182), and Zimbra webmail software.
- Victims mainly include governmental and defense organizations in Eastern Europe, with additional targets in Africa, Europe, and South America.
- SpyPress JavaScript payloads (HORDE, MDAEMON, ROUNDCUBE, ZIMBRA) steal credentials, email messages, contacts, and even two-factor authentication secrets.
- SpyPress.MDAEMON uniquely bypasses two-factor authentication by exfiltrating 2FA secrets and creating application passwords.
- Payloads are executed when victims open malicious emails in vulnerable webmail portals, with some scripts creating Sieve rules to forward incoming emails to attackers.
- Communication with command and control servers uses HTTPS POST requests with base64-encoded data for exfiltration.
MITRE Techniques
- [T1583.001] Acquire Infrastructure: Domains â Sednit purchased domains at various registrars to support their operations (âSednit bought domains at various registrarsâ).
- [T1583.004] Acquire Infrastructure: Server â Sednit rented servers at multiple hosting providers, including M247 (âSednit rented servers at M247 and other hosting providersâ).
- [T1587.004] Develop Capabilities: Exploits â Sednit developed or acquired XSS exploits targeting Roundcube, Zimbra, Horde, and MDaemon (âSednit developed (or acquired) XSS exploits for Roundcube, Zimbra, Horde, and MDaemonâ).
- [T1587.001] Develop Capabilities: Malware â Sednit developed JavaScript stealers SpyPress to harvest data from webmail servers (âSednit developed JavaScript stealers⌠to steal data from webmail serversâ).
- [T1190] Exploit Public-Facing Application â Sednit exploited known and zero-day vulnerabilities in webmail software to execute malicious JavaScript (âSednit exploited known and zero-day vulnerabilities⌠to execute JavaScript codeâ).
- [T1203] Exploitation for Client Execution â SpyPress payloads execute when victims open malicious emails inside vulnerable webmail clients (âSpyPress payloads are executed when a victim opens the malicious emailâ).
- [T1027] Obfuscated Files or Information â SpyPress payloads are obfuscated using an unknown JavaScript obfuscator (âSpyPress payloads are obfuscated with an unknown JavaScript obfuscatorâ).
- [T1187] Forced Authentication â SpyPress payloads force victims to re-enter credentials by logging them out (âSpyPress payloads can log out users to entice them into entering their credentialsâ).
- [T1556.006] Modify Authentication Process: Multi-Factor Authentication â SpyPress.MDAEMON steals 2FA secrets and creates app passwords for bypass (âSpyPress.MDAEMON can steal the 2FA token and create an application passwordâ).
- [T1087.003] Account Discovery: Email Account â SpyPress collects user contact lists and account information (âSpyPress payloads get information about the email account, such as the contact listâ).
- [T1056.003] Input Capture: Web Portal Capture â SpyPress attempts to steal credentials via hidden input forms (âSpyPress payloads try to steal webmail credentials by creating a hidden login formâ).
- [T1119] Automated Collection â SpyPress automates collection of credentials and emails (âSpyPress payloads automatically collect credentials and email messagesâ).
- [T1114.002] Email Collection: Remote Email Collection â SpyPress collects and exfiltrates emails from victim mailboxes remotely (âSpyPress payloads collect and exfiltrate emailsâŚâ).
- [T1114.003] Email Collection: Email Forwarding Rule â SpyPress.ROUNDCUBE creates Sieve rules to forward incoming emails to attackers (âSpyPress.MDAEMON adds a Sieve rule to forward any incoming email messageâ).
- [T1071.001] Application Layer Protocol: Web Protocols â C2 communications are conducted using HTTPS (âC&C communication is done via HTTPSâ).
- [T1071.003] Application Layer Protocol: Mail Protocols â Email forwarding exfiltration uses mail protocols (âexfiltration is done via emailâ).
- [T1132.001] Data Encoding: Standard Encoding â Data exfiltrated is base64 encoded (âData is base64 encoded before being sent to the C&C serverâ).
- [T1020] Automated Exfiltration â SpyPress automatically exfiltrates data to C2 servers (âSpyPress payloads automatically exfiltrate credentials and email messagesâ).
- [T1041] Exfiltration Over C2 Channel â Data is exfiltrated over command and control channels (âSpyPress payloads exfiltrate data over the C&C channelâ).
Indicators of Compromise
- [File Hashes] SpyPress malware and exploit samples â 41FE2EFB38E0C7DD10E6009A68BD26687D6DBF4C (SpyPress.ZIMBRA), 1078C587FE2B246D618AF74D157F941078477579 (SpyPress.ROUNDCUBE), 8EBBBC9EB54E216EFFB437A28B9F2C7C9DA3A0FA (CVE-2024-11182 exploit), and others.
- [Email Addresses] Spearphishing sources â [email protected] (used in 2023 RoundPress campaigns), [email protected], and [email protected] (2024 campaigns targeting Ukrainian and Bulgarian victims).
- [Domains] Command and Control infrastructure â ceriossl.info (45.138.87.250), global-world-news.net (77.243.181.238), sqj.fr (185.225.69.223), tgh24.xyztuo.world (193.29.104.152), jiaw.shop (91.237.124.164), hijx.xyz (89.44.9.74), ikses.net (111.90.151.167), and others.
- [IP Addresses] Hosting C2 servers â 45.138.87.250, 77.243.181.238, 185.225.69.223, 193.29.104.152, 91.237.124.164, 89.44.9.74, 111.90.151.167, among others.
Read more: https://www.welivesecurity.com/en/eset-research/operation-roundpress/