SpyPress.HORDE is a JavaScript espionage payload in the SpyPress family used in Sednit’s Operation RoundPress. ESET assessed with medium confidence that the campaign is run by Sednit, also known as APT28, Fancy Bear, Forest Blizzard, and Sofacy. In 2024, the operation expanded beyond Roundcube to target Horde, MDaemon, and Zimbra webmail platforms by delivering spearphishing emails that exploit XSS vulnerabilities and inject malicious JavaScript into the victim’s webmail session. The payload executes only when the victim opens the malicious email in a vulnerable Horde webmail interface. Its purpose is to steal confidential data from selected email accounts. Across the SpyPress family, capabilities include theft of webmail credentials and exfiltration of mailbox data such as emails, contacts, and address-book information. The payloads are obfuscated, use randomized variable and function names, decrypt strings only when needed, and do not maintain true persistence; they are reloaded whenever the victim reopens the malicious email. Exfiltrated data is sent to hardcoded command-and-control servers via HTTP POST requests, typically with base64-encoded content. Operation RoundPress primarily targeted governmental entities and defense-related organizations, especially in Eastern Europe and particularly those connected to the war in Ukraine, while additional victims were observed in Africa, Europe, and South America. Reported SpyPress C2 infrastructure for the campaign included sqj[.]fr, tgh24[.]xyz, tuo[.]world, lsjb[.]digital, jiaw[.]shop, hfuu[.]de, raxia[.]top, rnl[.]world, hijx[.]xyz, and ikses[.]net.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In 2024, we have observed Sednit using four payloads in Operation RoundPress: SpyPress.HORDE, SpyPress.MDAEMON, SpyPress.ROUNDCUBE, and SpyPress.ZIMBRA. They are injected into the victims’ webmail context using XSS vulnerabilities.
"The attackers unleash JavaScript payloads SpyPress.HORDE, SpyPress.MDAEMON, SpyPress.ROUNDCUBE, and SpyPress.ZIMBRA upon the targets."
13 distinct techniques documented for this family, organized by ATT&CK tactic.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
JavaScript payload delivered via XSS in Horde webmail to steal credentials and exfiltrate mailbox data (address book/contacts/login history/email messages) accessible in the victim’s webmail session.
JavaScript payload for Horde webmail that steals webmail credentials by creating hidden input fields and exfiltrating them to a hardcoded C2 via HTTP POST.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.