# Operation RoundPress: TA458 Deploys SpyPress Malware via Half-Click Webmail Zero-Days (CVE-2025-27915, CVE-2025-3929, CVE-2026-8496)

> Russia-aligned espionage group TA458 continues Operation RoundPress, chaining 'half-click' XSS zero-days and n-days across Zimbra, mDaemon, SOGo, Kerio, and Roundcube webmail to deploy the JavaScript-based SpyPress malware framework, which steals credentials, contacts, and email. No link click or attachment open is required beyond viewing the malicious email/calendar invite.

- **Published:** 2026-07-23T00:00:00Z
- **Last reviewed:** 2026-07-23T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2579
- **ID:** TL-2026-2579
- **Severity:** CRITICAL (CVSS 9.9)
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** TA458 (Russia)
- **Detections:** 9 · **IOCs:** 19 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-8496, CVE-2025-27915, CVE-2025-3929, CVE-2023-43770, CVE-2024-42009, CVE-2025-49113

## Description

Proofpoint's 23 July 2026 report (part two of a series alongside a joint CISA/NSA/FBI advisory) documents TA458's continuation of Operation RoundPress, the webmail-exploitation espionage campaign first disclosed by ESET in May 2025 and assessed there with medium confidence to Sednit/APT28/Fancy Bear/Forest Blizzard (Russia's GRU). Proofpoint tracks the operators of this later wave under its own designation, TA458, distinguishing the cluster from TA422 (Sofacy/APT28) and from TA488 (Void Blizzard/Laundry Bear), a related Russia-aligned actor separately reported exploiting a different Zimbra zero-day (CVE-2025-66376) in the same joint advisory. Whether TA458 and Sednit/APT28 represent the same underlying group tracked under different vendor names, or a related-but-distinct cluster reusing the same tooling, is not resolved in the available sourcing and should be treated as an open attribution question.

The campaign's signature technique is the 'half-click' exploit: a malicious calendar invite (.ics) or HTML email is delivered to a target's inbox, and simply opening/viewing it in a vulnerable webmail client executes attacker JavaScript with no link click, attachment download, or credential entry required. Across the observed 2023-2026 timeline, TA458 has weaponized this pattern against five different webmail platforms in sequence: Roundcube (CVE-2020-35730, then CVE-2023-43770, then CVE-2024-42009, then the critical PHP-deserialization RCE CVE-2025-49113), MDaemon (CVE-2024-11182 as a zero-day, later CVE-2025-3929), Zimbra Classic Web Client (CVE-2024-27443, then the zero-day CVE-2025-27915 abusing the HTML5 <details>/ontoggle event handler in ICS attachments), Kerio Webmail (exploitation of an unpatched/outdated instance, no CVE assigned), and, newest, Alinto SOGo (CVE-2026-8496, an XSS zero-day discovered by Proofpoint in March 2026 via malicious SVG markup with an onrepeat handler embedded in an ICS invite description field, reported to the vendor and patched in SOGo 5.12.8).

On Roundcube specifically, TA458 has escalated beyond simple XSS: the SpyPress.ROUNDCUBE variant abuses the webmail's file-upload handler to trigger unsafe PHP object deserialization, using the Crypt_GPG_Engine class as a gadget chain to achieve arbitrary code execution on the mail server itself (not just the browser session), then plants any of six persistence/backdoor mechanisms - reverse shells via PHP fsockopen() or /dev/tcp, content-fetching loops via PHP get_file_contents, Python requests.get, or curl -k, and PHP webshells dropped at program/js/list.js.php, program/resources/blank.gif.php, plugins/password/password.js.php, and program/actions/mail/get.php.php.

The broader SpyPress family (documented in depth by ESET for the Horde, MDaemon, Roundcube, and Zimbra variants) is uniformly JavaScript, delivered entirely within the malicious email/invite with no separate dropper or persistence beyond the webmail session itself for the ESET-era samples, and is built to: (1) trick the browser or password manager into auto-filling webmail credentials into a hidden form for exfiltration, (2) enumerate and exfiltrate the address book and email messages (SpyPress.ZIMBRA caps at 80 emails/folder via SOAP API, polling every 4 hours; SpyPress.ROUNDCUBE caps at 150 emails per execution, polling every 2 hours), (3) on MDaemon, steal 2FA/TOTP secrets and abuse the App Password feature to mint a durable authenticated credential that survives outside the browser session and bypasses MFA, and (4) on Roundcube, install malicious Sieve mail-filter rules that silently forward a copy of every incoming email to an attacker-controlled address (srezoska@skiff.com was observed by ESET) - a persistence mechanism that survives even after the JavaScript payload itself stops running. Since February 2026, SpyPress samples have been obfuscated with a customized build of Obfuscator.io, and TA458 rotated to a new set of C2/exfiltration domains at the same time.

Targeting is overwhelmingly Ukrainian government, military, and defense-industrial entities, plus Eastern European government/military targets in Albania, Greece, Moldova, and Turkiye, with earlier ESET-documented waves also hitting Bulgarian, Romanian, Serbian, Cypriot, Cameroonian, and Ecuadorian government/defense/academic targets; outlier sectors in the current wave include chemical manufacturing, telecommunications, and technology firms. A recurring operational signature noted by both ESET and Proofpoint is that TA458 frequently sends exploit emails to organizations without first confirming they run the targeted webmail platform, i.e., minimal victim reconnaissance, consistent with a low-cost, high-volume exploitation-at-scale approach against a known vulnerable software population rather than tailored intrusions.

## MITRE ATT&CK

- T1566 Phishing
- T1190 Exploit Public-Facing Application
- T1203 Exploitation for Client Execution
- T1059.007 Command and Scripting Interpreter: JavaScript
- T1505.003 Server Software Component: Web Shell
- T1027 Obfuscated Files or Information
- T1556.006 Modify Authentication Process: Multi-Factor Authentication
- T1056.003 Input Capture: Web Portal Capture
- T1111 Multi-Factor Authentication Interception
- T1114.002 Email Collection: Remote Email Collection
- T1114.003 Email Collection: Email Forwarding Rule
- T1119 Automated Collection
- T1071.001 Application Layer Protocol: Web Protocols

## Sources

- [Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458](https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits)
- [Operation RoundPress: Sednit's webmail espionage campaign targeting high-value webmail servers](https://www.welivesecurity.com/en/eset-research/operation-roundpress/)
- [ESET Research uncovers Operation RoundPress: Russia-aligned Sednit targets entities linked to the Ukraine war](https://www.eset.com/us/about/newsroom/research/eset-research-uncovers-operation-roundpress-russia-aligned-sednit-targets-entities-linked-to-the-ukraine-war-to-steal-confidential-data/)
- [Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions](https://thehackernews.com/2026/07/critical-zimbra-flaw-could-let-crafted_0483473395.html)
- [TA488 Targets Zimbra Mailservers with Half-Click Exploits](https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits)
- [CVE-2025-27915: Zimbra Collaboration Suite XSS Vulnerability](https://www.sentinelone.com/vulnerability-database/cve-2025-27915/)
- [CVE-2025-3929: Stored XSS vulnerability in MDaemon Email Server](https://exploit-intel.com/vuln/CVE-2025-3929)
- [CVE-2023-43770 Roundcube Security Update 1.6.3](https://roundcube.net/news/2023/09/15/security-update-1.6.3-released)
- [CVE-2024-42009 Roundcube Security Updates 1.6.8 and 1.5.8](https://roundcube.net/news/2024/08/04/security-updates-1.6.8-and-1.5.8)
- [CVE-2025-49113 Roundcube Security Updates 1.6.11 and 1.5.10](https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10)
- [CVE-2026-8496: Alinto SOGo XSS Vulnerability](https://www.sentinelone.com/vulnerability-database/cve-2026-8496/)
- [SOGo v5.12.8 released](https://www.sogo.nu/news/2026/sogo-v5128-released.html)
- [CISA Known Exploited Vulnerabilities Catalog - CVE-2025-27915](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-27915)
- [CISA Known Exploited Vulnerabilities Catalog - CVE-2024-42009](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-42009)
- [Zimbra Zero-Day Exploited to Target Brazilian Military via Malicious ICS Files](https://thehackernews.com/2025/10/zimbra-zero-day-exploited-to-target.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2579
