Threat reportAPTTL-2026-2579

Operation RoundPress: TA458 Deploys SpyPress Malware via Half-Click Webmail Zero-Days (CVE-2025-27915, CVE-2025-3929, CVE-2026-8496)

criticalACTIVE

Operation RoundPress (TL-2026-2579), also tracked as Operation RoundPress, is a critical-severity advanced persistent threat campaign scored CVSS 9.9, first published 2026-07-23. It is attributed to TA458 (Russia) with medium confidence, affects Synacor Zimbra Collaboration Suite (Classic Web Client), references 6 CVEs (CVE-2026-8496, CVE-2025-27915, CVE-2025-3929), maps to 13 MITRE ATT&CK techniques (T1027, T1056.003, T1059.007), and is covered by 9 detection rules and 19 indicators of compromise.

CVSS
9.9/10Critical
CVEs
6Referenced vulnerabilities
Techniques
13MITRE ATT&CK
Actors
1TA458
Detection rules
9SPL · KQL · Sigma
IOCs
19Indicators of compromise

Key facts for TL-2026-2579

Threat ID
TL-2026-2579
Also known as
Operation RoundPress
Severity
CRITICAL
CVSS
9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution
TA458
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
government administration, military, defense-industrial, chemical, telecoms, technology, civil aviation, academic
Target regions
ukraine, 151 - Eastern Europe, albania, greece, moldova, Turkiye, bulgaria, romania, serbia, cyprus
Detection rules
9
Indicators of compromise
19

Malware and tooling in Operation RoundPress

Malware and tooling: SpyPress, Zimbra

How Operation RoundPress works

Russia-aligned espionage group TA458 continues Operation RoundPress, chaining 'half-click' XSS zero-days and n-days across Zimbra, mDaemon, SOGo, Kerio, and Roundcube webmail to deploy the JavaScript-based SpyPress malware framework, which steals credentials, contacts, and email. No link click or attachment open is required beyond viewing the malicious email/calendar invite.

Proofpoint's 23 July 2026 report (part two of a series alongside a joint CISA/NSA/FBI advisory) documents TA458's continuation of Operation RoundPress, the webmail-exploitation espionage campaign first disclosed by ESET in May 2025 and assessed there with medium confidence to Sednit/APT28/Fancy Bear/Forest Blizzard (Russia's GRU). Proofpoint tracks the operators of this later wave under its own designation, TA458, distinguishing the cluster from TA422 (Sofacy/APT28) and from TA488 (Void Blizzard/Laundry Bear), a related Russia-aligned actor separately reported exploiting a different Zimbra zero-day (CVE-2025-66376) in the same joint advisory. Whether TA458 and Sednit/APT28 represent the same underlying group tracked under different vendor names, or a related-but-distinct cluster reusing the same tooling, is not resolved in the available sourcing and should be treated as an open attribution question.

The campaign's signature technique is the 'half-click' exploit: a malicious calendar invite (.ics) or HTML email is delivered to a target's inbox, and simply opening/viewing it in a vulnerable webmail client executes attacker JavaScript with no link click, attachment download, or credential entry required. Across the observed 2023-2026 timeline, TA458 has weaponized this pattern against five different webmail platforms in sequence: Roundcube (CVE-2020-35730, then CVE-2023-43770, then CVE-2024-42009, then the critical PHP-deserialization RCE CVE-2025-49113), MDaemon (CVE-2024-11182 as a zero-day, later CVE-2025-3929), Zimbra Classic Web Client (CVE-2024-27443, then the zero-day CVE-2025-27915 abusing the HTML5 <details>/ontoggle event handler in ICS attachments), Kerio Webmail (exploitation of an unpatched/outdated instance, no CVE assigned), and, newest, Alinto SOGo (CVE-2026-8496, an XSS zero-day discovered by Proofpoint in March 2026 via malicious SVG markup with an onrepeat handler embedded in an ICS invite description field, reported to the vendor and patched in SOGo 5.12.8).

On Roundcube specifically, TA458 has escalated beyond simple XSS: the SpyPress.ROUNDCUBE variant abuses the webmail's file-upload handler to trigger unsafe PHP object deserialization, using the Crypt_GPG_Engine class as a gadget chain to achieve arbitrary code execution on the mail server itself (not just the browser session), then plants any of six persistence/backdoor mechanisms - reverse shells via PHP fsockopen() or /dev/tcp, content-fetching loops via PHP get_file_contents, Python requests.get, or curl -k, and PHP webshells dropped at program/js/list.js.php, program/resources/blank.gif.php, plugins/password/password.js.php, and program/actions/mail/get.php.php.

The broader SpyPress family (documented in depth by ESET for the Horde, MDaemon, Roundcube, and Zimbra variants) is uniformly JavaScript, delivered entirely within the malicious email/invite with no separate dropper or persistence beyond the webmail session itself for the ESET-era samples, and is built to: (1) trick the browser or password manager into auto-filling webmail credentials into a hidden form for exfiltration, (2) enumerate and exfiltrate the address book and email messages (SpyPress.ZIMBRA caps at 80 emails/folder via SOAP API, polling every 4 hours; SpyPress.ROUNDCUBE caps at 150 emails per execution, polling every 2 hours), (3) on MDaemon, steal 2FA/TOTP secrets and abuse the App Password feature to mint a durable authenticated credential that survives outside the browser session and bypasses MFA, and (4) on Roundcube, install malicious Sieve mail-filter rules that silently forward a copy of every incoming email to an attacker-controlled address (srezoska@skiff.com was observed by ESET) - a persistence mechanism that survives even after the JavaScript payload itself stops running. Since February 2026, SpyPress samples have been obfuscated with a customized build of Obfuscator.io, and TA458 rotated to a new set of C2/exfiltration domains at the same time.

Targeting is overwhelmingly Ukrainian government, military, and defense-industrial entities, plus Eastern European government/military targets in Albania, Greece, Moldova, and Turkiye, with earlier ESET-documented waves also hitting Bulgarian, Romanian, Serbian, Cypriot, Cameroonian, and Ecuadorian government/defense/academic targets; outlier sectors in the current wave include chemical manufacturing, telecommunications, and technology firms. A recurring operational signature noted by both ESET and Proofpoint is that TA458 frequently sends exploit emails to organizations without first confirming they run the targeted webmail platform, i.e., minimal victim reconnaissance, consistent with a low-cost, high-volume exploitation-at-scale approach against a known vulnerable software population rather than tailored intrusions.

MITRE ATT&CK techniques used in TL-2026-2579

Defense Evasion

T1027 Obfuscated Files or Information

Credential Access

T1056.003 Input Capture: Web Portal Capture; T1111 Multi-Factor Authentication Interception

Execution

T1059.007 Command and Scripting Interpreter: JavaScript; T1203 Exploitation for Client Execution

Command and Control

T1071.001 Application Layer Protocol: Web Protocols

Collection

T1114.002 Email Collection: Remote Email Collection; T1114.003 Email Collection: Email Forwarding Rule; T1119 Automated Collection

Initial Access

T1190 Exploit Public-Facing Application; T1566 Phishing

Persistence

T1505.003 Server Software Component: Web Shell

defense-impairment

T1556.006 Modify Authentication Process: Multi-Factor Authentication

Affected products and versions in Operation RoundPress

  • Synacor — Zimbra Collaboration Suite (Classic Web Client)
    Vulnerable versions: 9.0; 10.0; 10.1
    Fixed in: 9.0.1; 10.0.13; 10.1.5
  • MDaemon Technologies (Alt-N) — MDaemon Email Server
    Vulnerable versions: 22.0.0 through 25.0.1
    Fixed in: later than 25.0.1
  • Roundcube — Roundcube Webmail
    Vulnerable versions: < 1.4.14; 1.5.x < 1.5.10; 1.6.x < 1.6.11
    Fixed in: 1.4.14; 1.5.4; 1.5.8; 1.5.10; 1.6.3; 1.6.8; 1.6.11
  • Alinto — SOGo
    Vulnerable versions: 5.12.7 and earlier releases sharing the ICS-rendering logic
    Fixed in: 5.12.8
  • Kerio (GFI Software) — Kerio Connect Webmail
    Vulnerable versions: outdated/unpatched instances, no CVE assigned

Remediation for Operation RoundPress

Patches

  • Zimbra 9.0.1 / 10.0.13 / 10.1.5 (CVE-2025-27915)
  • MDaemon > 25.0.1 (CVE-2025-3929)
  • Roundcube 1.5.10 / 1.6.11 (CVE-2025-49113)
  • Roundcube 1.5.8 / 1.6.8 (CVE-2024-42009)
  • Roundcube 1.4.14 / 1.5.4 / 1.6.3 (CVE-2023-43770)
  • SOGo 5.12.8 (CVE-2026-8496)

Immediate actions

  • Patch Zimbra Collaboration Suite to 9.0.1, 10.0.13, or 10.1.5+ (CVE-2025-27915)
  • Patch MDaemon Email Server beyond 25.0.1 (CVE-2025-3929)
  • Patch Roundcube Webmail to 1.5.10 / 1.6.11+ (CVE-2025-49113) and 1.5.8 / 1.6.8+ (CVE-2024-42009) and 1.4.14 / 1.5.4 / 1.6.3+ (CVE-2023-43770)
  • Patch Alinto SOGo to 5.12.8+ (CVE-2026-8496)
  • Decommission or upgrade outdated Kerio Webmail instances
  • Block the identified SpyPress C2 domains at email/web gateways

Workarounds

  • Strip/disable HTML5 <details>/ontoggle and SVG animation event handlers (onrepeat/onbegin/onend) in server-side HTML sanitization until patched
  • Restrict webmail file-upload handler access on unpatched Roundcube deployments

Longer-term hardening

  • Deploy CSP and strict HTML/ICS sanitization on all self-hosted webmail front ends
  • Disable or tightly restrict inbound calendar-invite (ICS) auto-rendering for external senders
  • Monitor for anomalous Sieve/mail-filter rule creation and unexpected App Password/2FA-secret generation events
  • Hunt for webshells at known Roundcube plugin/action paths and unexplained outbound fsockopen/curl/requests activity from the mail server host

CVEs associated with Operation RoundPress

CVE-2026-8496, CVE-2025-27915, CVE-2025-3929, CVE-2023-43770, CVE-2024-42009, CVE-2025-49113

Weaknesses (CWE) in Operation RoundPress

CWE-79, CWE-502

Timeline of Operation RoundPress

  • Roundcube patches CVE-2023-43770 (XSS via crafted links in plain-text emails) in version 1.6.3; TA458 begins exploiting it as an n-day the following May.
  • TA458 observed exploiting CVE-2023-43770 against Roundcube instances (exploit email hash 625e4c16...10dbf8).
  • Roundcube patches the critical CVE-2024-42009 (CVSS 9.3, mailbox-content theft via crafted message) in versions 1.5.8/1.6.8; CISA adds it to the KEV catalog.
  • TA458 conducts Zimbra (CVE-2025-27915) and Roundcube (CVE-2024-42009) exploitation waves; exploit-email hashes fb8ec4db...41dd34 and 3a449148...4ce9ba first observed.
  • TA458 exploit email using CVE-2025-3929 against MDaemon observed (hash 8b5a4dc2...31cd5b7f).
  • StrikeReady observes in-the-wild zero-day exploitation of CVE-2025-27915 against Zimbra Classic Web Client; ANSSI separately publishes a document on related TA422 targeting.
  • MDaemon patches CVE-2025-3929 (stored XSS via crafted img-tag HTML email) after CVSS 6.1 disclosure.
  • Following ESET's publication, TA458 expands its targeted webmail platform scope, later adding Kerio and SOGo.
  • ESET publishes the original Operation RoundPress research, attributing the campaign with medium confidence to Sednit/APT28, documenting SpyPress variants for Horde, MDaemon, Roundcube, and Zimbra, and listing nine C2 domains/IPs.
  • Roundcube patches the critical CVE-2025-49113 (CVSS 9.9, unauthenticated-adjacent PHP object deserialization RCE via unvalidated _from parameter) in versions 1.5.10/1.6.11.
  • SpyPress payloads begin shipping obfuscated with a customized build of Obfuscator.io; new C2 domains xsza.net, zxzaq.com, and upgybj.store come online.
  • Exploit emails tied to CVE-2025-49113 and to the new CVE-2026-8496 SOGo zero-day observed (hashes 6b2c02bf...aede139a and e27d1bf8...7808d288).
  • Proofpoint discovers TA458 exploiting a zero-day XSS in Alinto SOGo (malicious SVG/onrepeat handler in an ICS invite description), reports it to the vendor, and it is patched as CVE-2026-8496 in SOGo 5.12.8; TA458 exploitation of outdated Kerio Webmail also observed; Hunt.io separately publishes findings on a related campaign it names Operation Roundish (APT28).
  • Proofpoint publishes 'Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458,' part two of its analysis, detailing the SOGo zero-day, the Kerio exploitation, and TA458's continued targeting of Ukrainian and Eastern European government/military entities.
  • CISA, NSA, FBI, and international partners issue a joint advisory on Russian state-supported phishing/webmail-exploitation activity, covering both TA458 (Operation RoundPress/SOGo zero-day) and the related actor TA488 (Void Blizzard/Laundry Bear, exploiting a separate Zimbra zero-day, CVE-2025-66376).

Sources cited for Operation RoundPress

Detection coverage for TL-2026-2579

As of 2026-07-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2579 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
19 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats