TA458 is a Russia-aligned espionage threat actor associated with Operation RoundPress and assessed as likely linked to the Russian GRU, although attribution to a specific GRU unit remains unsubstantiated. The group specializes in compromising webmail platforms through "half-click" exploitation, in which a victim is compromised simply by opening a malicious email in a webmail client. TA458 has targeted multiple webmail products, including Zimbra, Roundcube, mDaemon, Kerio, and SOGo, and has exploited both zero-day and n-day vulnerabilities, including CVE-2026-8496 in SOGo, CVE-2025-27915 in Zimbra, CVE-2025-3929 in mDaemon, CVE-2023-43770 and CVE-2024-42009 in Roundcube, and CVE-2025-49113 in a Roundcube deserialization chain for arbitrary code execution. The actor primarily targets Ukrainian government entities and military and government organizations across Eastern Europe, with observed targeting in Albania, Greece, Moldova, and Türkiye. Occasional targeting has also included chemical, telecommunications, and technology organizations. TA458’s operations are focused on espionage and theft of sensitive email data. TA458 uses the JavaScript malware family SpyPress, which is adapted to the specific webmail platform under attack while preserving core functions such as theft of credentials, contacts, and emails. In some Roundcube intrusions, SpyPress evolved beyond browser-session theft into interactive backdoor functionality intended to secure long-term access. The actor has been observed establishing persistence through multiple fallback mechanisms, including server-side backdoors and webshell-style access paths, and using compromised or actor-controlled accounts to distribute exploit emails. TA458 has also used proxy infrastructure as jump boxes during delivery operations. The group’s known capabilities include initial access via phishing emails and webmail exploitation, credential theft, email and contact exfiltration, long-term persistence, reconnaissance within compromised mail environments, defense evasion through obfuscation, and post-exploitation activity including arbitrary code execution and server-side backdooring. TA458 is widely tracked as the actor behind Operation RoundPress.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
In March 2026, the group exploited a zero-day flaw in SOGo webmail, later patched as CVE-2026-8496 in version 5.12.8.
SpyPress uses a second Roundcube exploit (CVE-2025-49113) that abuses Roundcube's file upload handler to trigger unsafe PHP deserialization. The end goal is to trigger arbitrary code execution and install multiple backdoor or persistence mechanisms.
Observed targets now span Zimbra (CVE-2025-27915), mDaemon (CVE-2025-3929), Roundcube (CVE-2024-42009, CVE-2023-43770), Kerio, and SOGo (CVE-2026-8496).
Observed targets now span Zimbra (CVE-2025-27915), mDaemon (CVE-2025-3929), Roundcube (CVE-2024-42009, CVE-2023-43770), Kerio, and SOGo (CVE-2026-8496).
Observed targets now span Zimbra (CVE-2025-27915), mDaemon (CVE-2025-3929), Roundcube (CVE-2024-42009, CVE-2023-43770), Kerio, and SOGo (CVE-2026-8496).
2 more CVEs tied to this actor tracked in Mallory.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exploiting the Half-click vulnerability in webmail platforms to harvest credentials, contacts, and emails and maintain persistence.
Acteurs de menace # ... TA458 (state-sponsored) ...
Conducting espionage-focused attacks against webmail platforms using half-click/XSS exploit chains to steal sensitive email data, including exploitation of a SOGo zero-day and use of SpyPress malware.
Russian military intelligence-linked activity cluster behind Operation RoundPress, targeting webmail platforms including Zimbra, Kerio, SOGo, mDaemon, and Roundcube using half-click XSS and other exploits to steal data and later establish long-term interactive backdoor access via SpyPress.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.