SpyPress.MDAEMON is an obfuscated JavaScript webmail payload used in Operation RoundPress. It is injected into vulnerable MDaemon webmail instances via spearphishing emails that exploit cross-site scripting (XSS) flaws; execution occurs when the victim opens the malicious email in a vulnerable webmail portal. ESET reported that Operation RoundPress is assessed with medium confidence to be run by Sednit, also known as APT28, Fancy Bear, Forest Blizzard, and Sofacy. The campaign’s goal is to steal confidential data from selected email accounts.
Based on the provided content, SpyPress.MDAEMON can steal webmail credentials, exfiltrate contacts, login history, email messages, and the victim’s two-factor authentication secret, and create an application password to bypass MFA. Like other SpyPress variants, it uses obfuscation with randomized variable and function names and decrypts strings only when needed. The payload does not have true persistence and is reloaded when the victim reopens the malicious email. Stolen data is exfiltrated to hardcoded command-and-control servers via HTTP POST requests, typically with base64-encoded content.
The malware was observed in 2024 as part of attacks against MDaemon alongside other webmail platforms including Roundcube, Horde, and Zimbra. The operation primarily targeted governmental entities and defense-related organizations, especially in Eastern Europe and particularly those connected to the war in Ukraine, with additional victims in Africa, Europe, and South America. The MDaemon activity included exploitation of CVE-2024-11182, a zero-day XSS vulnerability later patched in MDaemon version 24.5.1. Reported SpyPress infrastructure included domains such as sqj[.]fr, tgh24[.]xyz, tuo[.]world, lsjb[.]digital, jiaw[.]shop, hfuu[.]de, raxia[.]top, rnl[.]world, hijx[.]xyz, and ikses[.]net.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
MDaemon CVE-2024-11182 5.3 XSS Zero-day. ESET обнаружила его 1 ноября 2024, патч вышел 14 ноября в MDaemon 24.5.1.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SpyPress.MDAEMON is a JavaScript payload injected into vulnerable MDaemon webmail instances. Once deobfuscated, it reveals more functionality than what was implemented in SpyPress.HORDE: credential stealing, exfiltration of contacts and login history, exfiltration of email messages, exfiltration of the two-factor authentication secret, and creation of an App Password.
"The attackers unleash JavaScript payloads SpyPress.HORDE, SpyPress.MDAEMON, SpyPress.ROUNDCUBE, and SpyPress.ZIMBRA upon the targets."
17 distinct techniques documented for this family, organized by ATT&CK tactic.
SpyPress payloads try to steal webmail credentials by creating a hidden login form, to trick the browser and password managers into filling the credentials.
SpyPress payloads try to steal webmail credentials by creating a hidden login form, to trick the browser and password managers into filling the credentials.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
JavaScript payload delivered via XSS in MDaemon webmail to steal credentials and exfiltrate mailbox data; additionally can bypass 2FA by exfiltrating the 2FA secret and creating an app password for continued mailbox access.
JavaScript webmail stealer for MDaemon that steals credentials, contacts, login history, email messages, and 2FA secrets, and creates an application password to bypass 2FA and maintain mailbox access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.