SpyPress.ZIMBRA is a JavaScript payload used in Operation RoundPress, an espionage campaign that ESET assessed with medium confidence is operated by Sednit, also known as APT28, Fancy Bear, Forest Blizzard, and Sofacy. The payload is injected into vulnerable Zimbra webmail instances via spearphishing emails that exploit XSS vulnerabilities; Sednit exploited CVE-2024-27443, also tracked as ZBUG-3730, in Zimbra. The malicious code is embedded in the HTML body of phishing emails and executes only when the victim opens the email in a vulnerable Zimbra webmail portal. Once executed in the victim’s browser context, SpyPress.ZIMBRA steals webmail credentials and exfiltrates mailbox data, including contacts, settings, and email messages. ESET specifically noted that SpyPress.ZIMBRA uses SOAP requests to collect contacts and email data from Zimbra. Like the other SpyPress payloads, it is obfuscated, uses randomized variable and function names, decrypts strings only when needed, lacks true persistence, and is reloaded whenever the victim reopens the malicious email. Exfiltrated data is sent to hardcoded command-and-control servers via HTTP POST requests, typically with base64-encoded content. Operation RoundPress primarily targeted governmental entities and defense-related organizations, especially in Eastern Europe and particularly those connected to the war in Ukraine, while also affecting governments in Africa, Europe, and South America.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
For Zimbra, Sednit uses CVE-2024-27443 (also tracked as ZBUG-3730). It was patched on March 1st, 2024... The vulnerability lies in failing to sanitize the cif attribute. | SpyPress.ZIMBRA is the JavaScript payload injected into vulnerable Zimbra webmail instances. Once deobfuscated, it reveals similar functionalities to the previous payloads: credential stealing, exfiltration of contacts and settings, and exfiltration of email messages.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SpyPress.ZIMBRA is the JavaScript payload injected into vulnerable Zimbra webmail instances. Once deobfuscated, it reveals similar functionalities to the previous payloads: credential stealing, exfiltration of contacts and settings, and exfiltration of email messages.
"The attackers unleash JavaScript payloads SpyPress.HORDE, SpyPress.MDAEMON, SpyPress.ROUNDCUBE, and SpyPress.ZIMBRA upon the targets."
15 distinct techniques documented for this family, organized by ATT&CK tactic.
SpyPress payloads try to steal webmail credentials by creating a hidden login form, to trick the browser and password managers into filling the credentials.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
JavaScript payload delivered via XSS in Zimbra webmail to steal credentials and exfiltrate mailbox data (address book/contacts/login history/email messages) accessible in the victim’s webmail session.
JavaScript payload for Zimbra that steals credentials and exfiltrates contacts, settings, and email messages from compromised webmail sessions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.