TA458, a Russia-aligned espionage actor tracked as the operator behind Operation RoundPress, continues leveraging half-click XSS exploits against webmail platforms (SOGo, Kerio, Zimbra, mDaemon, Roundcube) to compromise government and military targets across Ukraine and Eastern Europe without requiring victim interaction beyond viewing a malicious email. The actor deploys the customized, obfuscated SpyPress JavaScript implant to steal credentials, contacts, and emails, and has recently pivoted its Roundcube variant toward establishing long-term server access via a chained PHP deserialization exploit (CVE-2025-49113) that installs multiple redundant reverse-shell and webshell persistence mechanisms.
TA458
1 post
Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458