SpyPress is an obfuscated JavaScript malware family used in webmail-focused espionage operations associated with Operation RoundPress and linked with medium confidence to APT28, while later reporting also tracks its use by the Russia-aligned cluster TA458. It is designed to execute in the context of a victim’s authenticated webmail session after exploitation of cross-site scripting and related flaws in internet-facing mail platforms. Documented target platforms include Roundcube, Horde, MDaemon, Zimbra, Kerio, and SOGo, with one variant tailored to each webmail environment.
Its core purpose is mailbox compromise and intelligence collection. Across observed variants, SpyPress steals webmail credentials, harvests email messages and contact data, and in some cases captures login history, two-factor authentication material, or application-specific passwords to preserve access. On Roundcube, some variants can create server-side mail-forwarding rules for durable collection of incoming correspondence. Reporting also describes uncommon browser-based credential theft techniques, including hidden form-field injection to capture password-manager autofill values.
SpyPress is typically delivered through exploit-laden emails that require little or no user interaction beyond opening the message in a vulnerable webmail client. The malicious code is embedded in the HTML body and runs as a half-click XSS payload inside the browser session of the logged-in user. Campaigns using SpyPress have targeted primarily government, military, diplomatic, and defense-related organizations, especially in Ukraine and Eastern Europe, with additional victims observed in other regions.
Later activity shows the malware evolving beyond mailbox theft. Since at least mid-2025, Roundcube-focused SpyPress variants were modified to support longer-term server access by chaining client-side compromise with server-side exploitation, including unsafe PHP deserialization leading to arbitrary code execution. Those variants attempted multiple fallback persistence and backdoor mechanisms, including reverse-shell style access, remote content retrieval, and dropped webshells. This evolution indicates that SpyPress is not only a browser-resident collection implant but, in some deployments, a bridge from webmail exploitation to broader post-exploitation on the mail server.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In March 2026, the group exploited a zero-day flaw in SOGo webmail, later patched as CVE-2026-8496 in version 5.12.8. | TA458 also continues using the SpyPress JavaScript malware, adapting it to different webmail platforms to support espionage and email theft.
SpyPress uses a second Roundcube exploit (CVE-2025-49113) that abuses Roundcube's file upload handler to trigger unsafe PHP deserialization. The end goal is to trigger arbitrary code execution and install multiple backdoor or persistence mechanisms. | TA458 continues to use SpyPress - an obfuscated JavaScript-based malware seen in Operation RoundPress - which the adversary modifies based on the targeted mail server.
Observed targets now span Zimbra (CVE-2025-27915), mDaemon (CVE-2025-3929), Roundcube (CVE-2024-42009, CVE-2023-43770), Kerio, and SOGo (CVE-2026-8496). | TA458 runs the operation ESET named RoundPress. Its SpyPress malware adapts to whichever platform it lands on.
In total, Proofpoint has observed TA458 exploiting the following webmail vulnerabilities: CVE-2024-42009: Roundcube (n-day) | TA458 continues to use SpyPress - an obfuscated JavaScript-based malware seen in Operation RoundPress - which the adversary modifies based on the targeted mailserver.
Observed targets now span Zimbra (CVE-2025-27915), mDaemon (CVE-2025-3929), Roundcube (CVE-2024-42009, CVE-2023-43770), Kerio, and SOGo (CVE-2026-8496). | TA458 runs the operation ESET named RoundPress. Its SpyPress malware adapts to whichever platform it lands on.
In total, Proofpoint has observed TA458 exploiting the following webmail vulnerabilities: CVE-2023-43770: Roundcube (n-day) | TA458 continues to use SpyPress - an obfuscated JavaScript-based malware seen in Operation RoundPress - which the adversary modifies based on the targeted mailserver.
Анатомия JavaScript implant: SpyPress и Roundish toolkit. По данным Hunt.io (Operation Roundish) и ESET (Operation RoundPress), JavaScript implant выполняет до шести операций за одну XSS-инъекцию.
Анатомия JavaScript implant: SpyPress и Roundish toolkit. По данным Hunt.io (Operation Roundish) и ESET (Operation RoundPress), JavaScript implant выполняет до шести операций за одну XSS-инъекцию.
Анатомия JavaScript implant: SpyPress и Roundish toolkit. По данным Hunt.io (Operation Roundish) и ESET (Operation RoundPress), JavaScript implant выполняет до шести операций за одну XSS-инъекцию.
"...Roundcube (CVE-2023-43770), and Zimbra (CVE-2024-27443) leveraged security defects already known and patched..." | Successful exploitation leads to the execution of an obfuscated JavaScript payload named SpyPress that comes with the ability to steal webmail credentials and harvest email messages and contact information from the victim's mailbox.
Successful exploitation leads to the execution of an obfuscated JavaScript payload named SpyPress that comes with the ability to steal webmail credentials and harvest email messages and contact information from the victim's mailbox.
Successful exploitation leads to the execution of an obfuscated JavaScript payload named SpyPress that comes with the ability to steal webmail credentials and harvest email messages and contact information from the victim's mailbox.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TA458 also continues using the SpyPress JavaScript malware, adapting it to different webmail platforms to support espionage and email theft.
Анатомия JavaScript implant: SpyPress и Roundish toolkit. По данным Hunt.io (Operation Roundish) и ESET (Operation RoundPress), JavaScript implant выполняет до шести операций за одну XSS-инъекцию.
We identified 14 TTP overlaps between the Roundish toolkit and ESET's documented Operation RoundPress campaign... Its presence in both SpyPress and Roundish strongly suggests a shared developer or development playbook.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The disclosure also follows a report from Proofpoint about Russian threat actor's continued webmail targeting using half-click cross-site scripting (XSS) exploits to siphon valuable data as part of a campaign referred to as Operation RoundPress.
TA458 also continues using the SpyPress JavaScript malware, adapting it to different webmail platforms to support espionage and email theft. | The campaign relies on advanced XSS vulnerabilities to steal sensitive email data without requiring clicks or social engineering.
Mail forwarding - скрипт addRedirectMailBox.js создаёт правило пересылки на контролируемый адрес... Это persistence без бэкдора
Credential harvesting - инъекция скрытых полей username/password с visibility:hidden и autocomplete=on . При любом клике пользователя перехватываются значения, автозаполненные менеджером паролей браузера.
Credential harvesting - инъекция скрытых полей username/password с visibility:hidden и autocomplete=on . При любом клике пользователя перехватываются значения, автозаполненные менеджером паролей браузера.
Email exfiltration - выгрузка писем через Roundcube API viewsource с base64-кодированием и HTTP POST на C2.
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
JavaScript malware used by TA458 against webmail platforms to support espionage and steal sensitive email data.
An obfuscated JavaScript-based malware used in Operation RoundPress and adapted per targeted mail server; later variants added interactive backdoor mechanisms for long-term access.
A cross-platform espionage malware used in TA458's RoundPress activity against webmail platforms. It adapts to the target platform and attempts multiple persistence methods, including reverse shells and dropped webshells, to maintain long-term access after exploitation.
JavaScript implant used in webmail attacks to harvest credentials, create hidden mail-forwarding rules for persistence, exfiltrate emails and contacts, extract 2FA/TOTP secrets and application passwords, and abuse CSS side-channels to steal CSRF tokens.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.