TA458 is a Russia-aligned espionage threat actor associated with Operation RoundPress and the SpyPress malware family. The group is assessed with moderate confidence to be linked to the Russian state, likely operating in support of the GRU, although attribution to a specific GRU unit remains unsubstantiated. TA458 specializes in compromising webmail environments to collect sensitive communications and credentials. Its operations have focused primarily on Ukrainian government entities and military or government organizations across Eastern Europe, including targets in Albania, Greece, Moldova, and Türkiye. Reporting also indicates occasional targeting of organizations in the chemical, telecommunications, and technology sectors. A defining characteristic of TA458 activity is the use of so-called half-click exploitation, in which a victim can be compromised simply by opening a malicious email within a vulnerable webmail client. The group has targeted multiple webmail platforms, including Zimbra, Roundcube, mDaemon, Kerio, and SOGo, and has exploited both zero-day and n-day vulnerabilities in those products. Publicly associated vulnerabilities include CVE-2025-27915, CVE-2025-3929, CVE-2023-43770, CVE-2024-42009, CVE-2025-49113, and CVE-2026-8496. TA458 deploys SpyPress, a JavaScript-based malware framework that adapts to the compromised webmail platform while maintaining core espionage functionality. SpyPress is used to steal credentials, contacts, and email content from authenticated sessions. The malware has employed customized obfuscation and platform-specific variants to support exploitation and post-compromise collection. On Roundcube, TA458 has been observed evolving beyond browser-session theft toward longer-term server-side access. In some operations, the group chained client-side exploitation with CVE-2025-49113 to trigger unsafe PHP deserialization and achieve arbitrary code execution on the mail server. SpyPress then attempted multiple fallback persistence and backdoor mechanisms, including reverse-shell style access, remote retrieval and execution of additional content, and deployment of webshells, indicating an intent to preserve durable access even if one mechanism failed. Operationally, TA458 has used both actor-controlled and compromised email accounts to distribute exploit-bearing messages, helping malicious emails appear legitimate and improving delivery into trusted communication flows. The group has also used intermediary infrastructure to relay some operations. No confirmed overlap has been established between TA458 and TA422, also known as APT28, Fancy Bear, Sofacy, or Forest Blizzard. Overall, TA458 is a capable and persistent Russian-aligned cyber-espionage actor distinguished by sustained exploitation of webmail software, rapid adoption of newly discovered vulnerabilities, and a focus on stealing high-value diplomatic, governmental, and military communications.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
Observed targets now span Zimbra (CVE-2025-27915), mDaemon (CVE-2025-3929), Roundcube (CVE-2024-42009, CVE-2023-43770), Kerio, and SOGo (CVE-2026-8496).
Observed targets now span Zimbra (CVE-2025-27915), mDaemon (CVE-2025-3929), Roundcube (CVE-2024-42009, CVE-2023-43770), Kerio, and SOGo (CVE-2026-8496).
Observed targets now span Zimbra (CVE-2025-27915), mDaemon (CVE-2025-3929), Roundcube (CVE-2024-42009, CVE-2023-43770), Kerio, and SOGo (CVE-2026-8496).
In total, Proofpoint has observed TA458 exploiting the following webmail vulnerabilities: CVE-2025-3929: mDaemon (zero-day)
On Roundcube, the group changed strategy. It chained a second flaw, CVE-2025-49113, to reach unsafe deserialization and arbitrary code execution.
2 more CVEs tied to this actor tracked in Mallory.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russia-aligned espionage group conducting repeated webmail zero-day exploitation across multiple platforms including Zimbra, mDaemon, Roundcube, Kerio, and SOGo, using SpyPress and additional persistence mechanisms for long-term access.
Russian-aligned espionage actor conducting webmail exploitation campaigns using half-click XSS and related exploits to steal emails, credentials, and contacts, and in some cases establish long-term access via backdoors/webshells.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.