SpyPress.ROUNDCUBE is a malicious JavaScript payload used in ESET-tracked Operation RoundPress. It is injected into vulnerable Roundcube webmail instances via spearphishing emails that exploit XSS flaws in the webmail interface; the payload executes when the victim opens the malicious email in a vulnerable Roundcube portal. ESET reported Roundcube exploitation in 2023 and 2024, including CVE-2020-35730 and CVE-2023-43770. The broader campaign is assessed with medium confidence by ESET to be run by Sednit, also known as APT28, Fancy Bear, Forest Blizzard, and Sofacy, with the goal of stealing confidential data from selected email accounts. Observed targeting primarily involved governmental entities and defense-related organizations, especially in Eastern Europe and organizations connected to the war in Ukraine, with additional victims in Africa, Europe, and South America. Once deobfuscated, SpyPress.ROUNDCUBE is described as having functionality similar to SpyPress.MDAEMON: credential theft, exfiltration of the address book and the about page, exfiltration of emails, and creation of malicious Sieve rules. Some samples can log victims out and capture credentials when they reauthenticate through the legitimate login form, and some create Sieve rules that forward copies of incoming emails to an attacker-controlled address. The payload is obfuscated, uses randomized variable and function names, decrypts strings only when needed, lacks true persistence, and is reloaded whenever the victim reopens the malicious email. SpyPress payloads exfiltrate stolen data to hardcoded command-and-control servers via HTTP POST requests, typically with base64-encoded content. Reported SpyPress C2 infrastructure includes sqj[.]fr, tgh24[.]xyz, tuo[.]world, lsjb[.]digital, jiaw[.]shop, hfuu[.]de, raxia[.]top, rnl[.]world, hijx[.]xyz, and ikses[.]net.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On September 29th, 2023, we detected a spearphishing email, part of Operation RoundPress, sent from katecohen1984@portugalmail[.]pt. The email exploited CVE-2023-43770 in Roundcube... in 2024, it switched to CVE-2023-43770. | SpyPress.ROUNDCUBE is the JavaScript payload injected into vulnerable Roundcube webmail instances. Once deobfuscated, it reveals similar functionalities to what is implemented in SpyPress.MDAEMON: credential stealing, exfiltration of the address book and the about page, exfiltration of emails, and malicious Sieve rules.
In 2023, Sednit was exploiting CVE-2020-35730, a known XSS vulnerability in Roundcube... which enables the loading of arbitrary JavaScript code in the context of the webmail window. | SpyPress.ROUNDCUBE is the JavaScript payload injected into vulnerable Roundcube webmail instances. Once deobfuscated, it reveals similar functionalities to what is implemented in SpyPress.MDAEMON: credential stealing, exfiltration of the address book and the about page, exfiltration of emails, and malicious Sieve rules.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SpyPress.ROUNDCUBE is the JavaScript payload injected into vulnerable Roundcube webmail instances. Once deobfuscated, it reveals similar functionalities to what is implemented in SpyPress.MDAEMON: credential stealing, exfiltration of the address book and the about page, exfiltration of emails, and malicious Sieve rules.
"The attackers unleash JavaScript payloads SpyPress.HORDE, SpyPress.MDAEMON, SpyPress.ROUNDCUBE, and SpyPress.ZIMBRA upon the targets."
18 distinct techniques documented for this family, organized by ATT&CK tactic.
SpyPress payloads try to steal webmail credentials by creating a hidden login form, to trick the browser and password managers into filling the credentials.
SpyPress payloads collect and exfiltrate emails, from the victim’s mailbox.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
JavaScript payload delivered via XSS in Roundcube webmail to steal credentials and exfiltrate mailbox data (address book/contacts/login history/email messages) accessible in the victim’s webmail session.
JavaScript payload for Roundcube that steals credentials, exfiltrates address book and emails, logs victims out to prompt credential reentry, and can create malicious Sieve forwarding rules for ongoing email theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.