Researchers and government agencies reported that the Russia-linked APT28 espionage cluster has continued and expanded Operation RoundPress, a campaign that compromises vulnerable webmail platforms when targets open specially crafted phishing emails. ESET said the operation began against Roundcube and later spread to Horde, MDaemon, and Zimbra, using cross-site scripting flaws to inject malicious JavaScript into active mail sessions and steal credentials, emails, contacts, and in some cases 2FA secrets and app passwords. Proofpoint said the activity persisted into 2026 with a new “half-click” zero-day in SOGo tracked as CVE-2026-8496, while also noting exploitation against Zimbra, MDaemon, Kerio, and Roundcube and a modified SpyPress chain that paired a Roundcube XSS vector with CVE-2025-49113 to pursue server-side code execution and longer-term access.
The victim set has centered on government, military, diplomatic, and defense-related organizations, especially in Ukraine and Eastern Europe, but reporting also identified targets in France, Africa, Europe, and South America. ANSSI said French entities have faced repeated APT28 intrusions since 2021 using phishing, webmail brute force, edge-device compromise, and exploitation of flaws including CVE-2023-23397, with recurring Roundcube-focused operations and credential theft infrastructure. CERT-UA separately linked a phishing campaign against Ukrainian local government bodies to UAC-0001/APT28 with medium confidence, citing infrastructure overlap with an earlier Roundcube compromise involving CVE-2023-43770 that stole mailbox credentials and created malicious mail-forwarding rules. Across the reporting, the campaign is described as a strategic intelligence-collection effort tied to Russian state interests and the war in Ukraine.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
Proofpoint observed TA458 modifying its Roundcube-focused SpyPress variant to chain a Roundcube XSS vector with CVE-2025-49113, enabling PHP deserialization and arbitrary code execution for longer-term server access.
Proofpoint said the SOGo zero-day used by TA458 was disclosed to Alinto and patched in SOGo version 5.12.8 as CVE-2026-8496.
Proofpoint reported that in March 2026 TA458 exploited a zero-day in SOGo webmail against government-focused targets using a half-click attack that triggered when victims opened a malicious email.
On July 15, 2026, Proofpoint reported that TA458 continued targeting government webmail servers with half-click exploits against SOGo, Zimbra, mDaemon, Kerio, and Roundcube, and assessed the actor is likely linked to the Russian GRU.
CERT-UA reported an ongoing phishing campaign targeting Ukrainian local self-government bodies with fake Google Sheets lures that trick users into executing PowerShell, leading to browser data theft, SSH tunneling, and Metasploit payload delivery. CERT-UA attributed the activity with medium confidence to UAC-0001 (APT28).
CERT-UA linked current activity to a September 2024 incident in which a Roundcube exploit, CVE-2023-43770, was used to steal mailbox credentials and create a mail-forwarding filter via the ManageSieve plugin.
ANSSI reported that APT28 activity affecting France in 2024 particularly emphasized governmental, diplomatic, and research targets.
ANSSI described a 2023 campaign in which APT28 used InfinityFree to deliver the HeadLace backdoor and Mocky.IO for command distribution.
On May 15, 2025, ESET published research on Operation RoundPress, describing a webmail-focused cyberespionage campaign and assessing with medium confidence that it is operated by Sednit/APT28.
ESET reported that Operation RoundPress used the MDaemon zero-day CVE-2024-11182 and that the flaw was patched in MDaemon version 24.5.1 after ESET disclosed it.
ESET said that in 2024 the RoundPress campaign expanded beyond Roundcube to target Horde, MDaemon, and Zimbra webmail servers, continuing to focus on governmental and defense-related organizations.
ESET reported that Operation RoundPress targeted Roundcube webmail servers in 2023 using spearphishing emails that exploited XSS flaws to inject malicious JavaScript into victims' webmail sessions.
The ANSSI report places APT28 espionage activity in the context of Russia's war against Ukraine, which began on February 24, 2022, and notes campaigns against Ukraine, NATO countries, and EU member states.
ANSSI and C4 partners reported observing the targeting and compromise of French entities by the APT28 intrusion set beginning in 2021 for strategic intelligence collection.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
proofpoint.com
Open sourcewelivesecurity.com
Open sourcecert.ssi.gouv.fr
Open sourcecert.gov.ua
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.