Proofpoint reports that TA458, a Russia-aligned espionage actor linked to Operation RoundPress, continues to use half-click webmail exploits to steal emails, credentials, and contacts from government and military targets. The campaign has leveraged vulnerabilities in Zimbra, mDaemon, Roundcube, Kerio, and SOGo, while the SpyPress payload has evolved toward long-term access and multiple persistence methods. #TA458 #OperationRoundPress #SpyPress #SOGo #Roundcube #Zimbra #mDaemon #Kerio
Keypoints
- TA458 remains focused on espionage against webmail servers using “half-click” exploits that work when a user simply opens a malicious email in webmail.
- The actor is assessed to be aligned with Russia’s GRU and is associated with Operation RoundPress.
- Proofpoint observed TA458 exploiting multiple webmail platforms, including Zimbra, mDaemon, Roundcube, Kerio, and SOGo.
- The group used SpyPress, an obfuscated JavaScript malware, to steal credentials, contacts, and emails, with behavior tailored to the target mailserver.
- TA458 shifted part of its Roundcube activity toward long-term access by adding backdoor and persistence mechanisms instead of only stealing data.
- The Roundcube variant used CVE-2025-49113 for unsafe PHP deserialization to enable arbitrary code execution and deploy fallback persistence methods, including reverse shells and webshells.
- Targets included Ukrainian government entities and military/government organizations across Eastern Europe, with some additional targeting of chemical, telecom, and technology firms.
MITRE Techniques
- [T1059.007] JavaScript – SpyPress used obfuscated JavaScript to steal data and run malicious logic in webmail sessions (‘SpyPress – an obfuscated JavaScript-based malware’).
- [T1059.006] Visual Basic? – Not mentioned in article.
- [T1059.004] Unix Shell – TA458 used a reverse bash shell for persistence and access (‘Open a reverse bash shell with bash -i >& /dev/tcp/ to the same C&C’).
- [T1059.003] Command and Scripting Interpreter: Windows Command Shell – Not mentioned in article.
- [T1055] Process Injection – Not mentioned in article.
- [T1059.007] JavaScript Execution via XSS – TA458 abused unsanitized webmail features and event handlers to execute arbitrary JavaScript (‘features in webmails that are not properly sanitized, such as event handlers that can be abused to execute arbitrary JavaScript’).
- [T1190] Exploit Public-Facing Application – TA458 exploited vulnerable webmail platforms including Zimbra, mDaemon, Roundcube, Kerio, and SOGo (‘exploiting vulnerabilities in Kerio and SOGo webmail platforms’).
- [T1210] Exploitation of Remote Services – The actor used webmail exploits against remotely accessible mail servers to gain access (‘target government webmail servers’).
- [T1071.001] Web Protocols – C2 and callbacks were carried over web-style requests and hosted domains (‘Use curl -k to fetch content from the domain’).
- [T1105] Ingress Tool Transfer – SpyPress fetched content from attacker-controlled domains using multiple methods (‘Use PHP get_file_contents to fetch content from a domain’).
- [T1505.003] Server Software Component: Web Shell – TA458 dropped PHP webshells into multiple web paths (‘Drop a basic PHP webshell to the following paths’).
- [T1053] Scheduled Task/Job – Not mentioned in article.
- [T1027] Obfuscated Files or Information – SpyPress used a customized variant of Obfuscator IO to hide payload logic (‘used a customized variant of the JavaScript obfuscation tool Obfuscator IO’).
- [T1204.001] Malicious Link – Not mentioned in article; the article emphasizes no user click is required.
- [T1190] Exploit Public-Facing Application: Cross-Site Scripting – TA458 relied on XSS flaws in webmail software (‘CVE-2025-27915: Zimbra (zero-day)’).
- [T1059.004] Command and Scripting Interpreter: Unix Shell – The payload used PHP fsockopen and curl to establish shells and fetch content (‘Open a reverse shell with PHP fsockopen() to TA458 C&C’).
- [T1068] Exploitation for Privilege Escalation – Not mentioned in article.
- [T1133] External Remote Services – TA458 targeted remote webmail services for initial access (‘half-click cross-site scripting (XSS) exploits in webmail software’).
- [T1211] Exploitation for Defense Evasion – Not mentioned in article.
- [T1041] Exfiltration Over C2 Channel – TA458 stole emails, contacts, and credentials through the malware’s interaction with C2 and webmail (‘theft of credentials, contacts, and emails’).
- [T1110] Brute Force – Not mentioned in article.
- [T1021] Remote Services – Not mentioned in article.
- [T1027.016] Junk Code – Not mentioned in article.
- [T1213] Data from Information Repositories – TA458 targeted email stores to collect mail, contacts, and credentials (‘theft of credentials, contacts, and emails’).
- [T1064] Scripting – TA458 used script-based payloads and PHP/Python/cURL logic for persistence and retrieval (‘Use Python requests.get to fetch content from the domain’).
- [T1059.001] PowerShell – Not mentioned in article.
- [T1059.005] Visual Basic – Not mentioned in article.
- [T1021.004] SSH – Not mentioned in article.
Indicators of Compromise
- [Domains] SpyPress C2 infrastructure – share-ya[.]space, xwe[.]us, and other 4 domains
- [SHA256 hashes] Exploit-laden email samples – 625e4c166c7a1d5a1becf56b27d4f76a2f95935cbd8d556c30a493263d10dbf8, a0c80cab70d6672b01710a70f93311fc1c1db2fbbf9cd6daa543c34b87e3444a, and other 5 hashes
- [File paths] Dropped PHP webshells used for persistence – program/js/list.js.php, program/resources/blank.gif.php, and other 2 paths
- [CVE identifiers] Exploited webmail vulnerabilities – CVE-2026-8496, CVE-2025-27915, and other 4 CVEs
- [Malware/Tool names] Payload and obfuscation tooling – SpyPress, Obfuscator IO
Read more: https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits