Skip to content
.ca
sign in

Threat intelligence from Proofpoint

7 reports on cyfar.ca summarizing Proofpoint research.

Proofpoint17 days ago12 minLLM reporthigh

Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458

TA458, a Russia-aligned espionage actor tracked as the operator behind Operation RoundPress, continues leveraging half-click XSS exploits against webmail platforms (SOGo, Kerio, Zimbra, mDaemon, Roundcube) to compromise government and military targets across Ukraine and Eastern Europe without requiring victim interaction beyond viewing a malicious email. The actor deploys the customized, obfuscated SpyPress JavaScript implant to steal credentials, contacts, and emails, and has recently pivoted its Roundcube variant toward establishing long-term server access via a chained PHP deserialization exploit (CVE-2025-49113) that installs multiple redundant reverse-shell and webshell persistence mechanisms.

Proofpoint17 days ago11 minLLM reporthigh

TA488 Targets Zimbra Mailservers with Half-Click Exploits

TA488, a Russia-aligned threat actor linked with medium confidence to Void Blizzard/Laundry Bear, exploited a zero-day flaw (CVE-2025-66376) in Zimbra's client-side HTML sanitizer using a tag-splitting technique with fake CSS @import directives to smuggle executable SVG/JavaScript payloads. The resulting malware, ZimReaper, requires only that a victim open/preview a crafted email in vulnerable Zimbra webmail to execute in the browser context, harvesting CSRF tokens, autofill credentials, and 2FA codes, establishing a persistent app-specific password bypassing MFA, and exfiltrating Global Address List data and up to 90 days of email via DNS tunneling and HTTP POST to Cloudflare-fronted C2 infrastructure. Targeting focused on Ukrainian government and US government/science/defense industrial base entities, with the campaign going dormant after public disclosure by Seqrite in early 2026.

Proofpoint20 days ago15 minLLM reporthigh

Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service

Cruciferra is a sophisticated Mono-based crypter-as-a-service offering used by multiple cybercrime threat clusters to obfuscate and deliver commodity malware including AsyncRAT, XWorm, zgRAT, AgentTesla, and others. It employs DLL side-loading for initial execution, then applies extensive defense-evasion techniques including indirect syscalls, API/IAT unhooking, BYOVD-based EDR tampering via vulnerable kernel drivers, UAC bypass, and a modified Process Ghosting variant that patches EDR inspection functions. The crypter uses over 90 polymorphically generated custom encryption algorithms derived from components of established ciphers, significantly complicating static analysis and signature-based detection.

Proofpointabout 1 month ago12 minLLM reporthigh

One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation

UNK_MassTraction, a suspected China-aligned threat cluster, has been exploiting chained n-day vulnerabilities in Roundcube mailservers (CVE-2024-42009 XSS followed by CVE-2025-49113 PHP deserialization) targeting physics and engineering departments at US and Canadian universities since May 2026. The campaign deploys a custom JavaScript credential stealer (IceCube), a webshell (SquareShell), and the VShell backdoor via an in-memory ELF loader, treating mailservers as edge devices for network pivot. The tooling demonstrates mature operational security including anti-forensics, fallback mechanisms, and process spoofing.

Proofpointabout 1 month ago18 minLLM reporthigh

Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency

UNK_DeadDrop is a likely North Korean threat actor conducting broad phishing campaigns targeting software developers with fake job offers and code review requests. The campaign delivers malicious GitHub/GitLab repositories that abuse VS Code and Cursor IDE task automation to silently execute cross-platform malware. Linux and macOS systems receive the Overlord Go RAT with custom credential and wallet theft modules, while Windows runs a fileless Node.js/Python pipeline inside the editor's Electron process. The malware exfiltrates cryptocurrency wallets, browser credentials, and OS keychain data to a hardcoded C&C server at 23.137.105.75:5173.

Proofpointabout 1 month ago10 minLLM reporthigh

Sayonara, SocGholish: Operation Endgame Disrupts Major Cybercrime Operation

Operation Endgame, a coordinated law enforcement action by Netherlands, Canada, US, and Germany, disrupted TA569's SocGholish web inject infrastructure by taking down over 100 servers and remediating 14,971 compromised websites. TA569 compromises legitimate websites—often WordPress installations—to inject obfuscated JavaScript that presents fake browser update pages to visitors, ultimately delivering GhoLoader malware which can lead to ransomware deployments. The attack chain leverages traffic direction systems (TA2726's Keitaro TDS and ParrotTDS) for victim filtering and uses advanced client-side blob URL construction to evade sandbox detection and network-based download tracing.

Proofpointabout 1 month ago10 minLLM reporthigh

StealC You Later: Proofpoint and IBM X-Force Support Operation Endgame Disruptions

Proofpoint and IBM X-Force collaborated with Europol and Microsoft's Digital Crimes Unit to disrupt the StealC malware-as-a-service ecosystem as part of Operation Endgame, seizing 66 domains, 296 servers, and over 25.6 million stolen credentials. Researchers discovered a directory traversal vulnerability in the StealC PHP C2 panel's filename handling during ZIP extraction, which was exploited by law enforcement to access and seize C2 servers. The teams also built a StealC bot emulator to track affiliate infrastructure and observe payload delivery chains, revealing StealC's loader functionality distributing a broad range of secondary malware including ransomware, RATs, and additional stealers.