Russia-aligned espionage groups TA458 and TA488 have been exploiting vulnerabilities in webmail platforms including Roundcube, Zimbra, SOGo, mDaemon, Kerio, and SOGo to compromise government and defense targets through so-called "half-click" attacks, where opening a malicious email in a webmail session triggers attacker-controlled JavaScript. Proofpoint reported TA458 used a SOGo zero-day later patched as CVE-2026-8496, while TA488 exploited a previously unknown Zimbra flaw assigned CVE-2025-66376 for months. The campaigns targeted Ukrainian government entities, Eastern European military and government organizations, and parts of the U.S. defense industrial base and nuclear sector, with malware such as SpyPress and ZimReaper stealing credentials, contacts, emails, CSRF tokens, and app-specific passwords to bypass multifactor protections.
Reporting on APT28 infrastructure exposed in early 2026 tied the broader Operation RoundPress activity to a larger webmail espionage program that relied heavily on patched but unremediated flaws, including CVE-2020-35730, CVE-2023-43770, CVE-2021-44026, and CVE-2020-12641 in Roundcube. Researchers said the leaked toolkit included XSS payloads, a Flask-based command-and-control server, a Go implant for GNU/Linux, operator bash history, and victim data, revealing poor operational security and overlap between staging, exfiltration, and pivot infrastructure. TA458 was also observed chaining a Roundcube XSS vector with CVE-2025-49113 to achieve PHP deserialization and arbitrary code execution, showing that the actors are pursuing not only mailbox theft and forwarding-rule abuse but also persistent server-side access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Proofpoint research summarized that TA488 used a previously unknown Zimbra vulnerability later assigned CVE-2025-66376 for at least five months in 2025. The group used a half-click technique in which opening an email triggered malicious JavaScript in the victim's authenticated webmail session.
A SecurityOnline report summarized Proofpoint's research on the Russia-aligned groups TA488 and TA458, including TA488's ZimReaper activity and TA458's Operation RoundPress targeting of multiple webmail platforms. It also noted U.S. government partners linked TA488 to Void Blizzard and described TA458 as likely GRU-directed according to Proofpoint.
The broader Operation RoundPress campaign was linked by ESET to targets in Ukraine, Bulgaria, and Romania, tying the webmail espionage activity to government-focused targeting in the region.
Proofpoint reported that TA458 continued targeting government webmail servers across platforms including Zimbra, mDaemon, Kerio, Roundcube, and SOGo using half-click exploits. The company also said TA458 modified its Roundcube-focused SpyPress variant to chain an XSS vector with CVE-2025-49113 for PHP deserialization and arbitrary code execution.
In March 2026, TA458 exploited a zero-day in SOGo webmail as part of Operation RoundPress. Proofpoint said the flaw was disclosed to Alinto and later patched as CVE-2026-8496 in SOGo version 5.12.8.
In January 2026, Hunt.io found an exposed directory on server 203.161.50.145 containing a full APT28 toolkit used in attacks against Roundcube webmail. The exposed contents reportedly included operator bash history, XSS payloads, a Flask-based C2, a Go implant, victim data, and links to Oracle Cloud pivot infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecodeby.net
Open sourceproofpoint.com
Open sourceproofpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.