ctipilot.ch

TA458

actor · actor:ta458-roundpress

Proofpoint's designation for the GRU-assessed, Russia-aligned espionage actor behind ESET's Operation RoundPress: runs a standing supply of 'half-click' webmail-client zero-days across Zimbra, mDaemon, Roundcube, Kerio and SOGo, deploying the per-client SpyPress payload to steal credentials, contacts and mail from Ukrainian and Eastern-European government/military targets. Proofpoint reports no telemetry overlap with TA422/APT28 and leaves the specific GRU unit unconfirmed (Proofpoint, 2026-07-23; ESET, 2025-05-15).

Aliases: Operation RoundPress

Coverage timeline
2
first 2026-07-25 → last 2026-07-25
Peak priority
high
1 high · 1 notable
Sources cited
5
4 hosts
Sections touched
2
deep-dive, updates
Co-occurring entities
4
see Related entities below
ATT&CK techniques
8
pinned v19.1 · see below
2026-07-252 appearances2026-07-25

Hunting pivots

Affected products
Zimbra Collaboration SuiteKerio ConnectMDaemon Email ServerRoundcube WebmailSOGo

ATT&CK techniques

8 techniques observed across 2 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-25/ta458-roundpress-webmail-zero-days-sogo-cve-2026-8496 · ATT&CK page ↗

T1566Phishing×2

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

Evidence: 2026-07-25/ta458-roundpress-webmail-zero-days-sogo-cve-2026-8496 · 2026-07-25/laundry-bear-zimreaper-app-password-persistence · ATT&CK page ↗

Execution TA0002

T1203Exploitation for Client Execution×2

Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility.

Evidence: 2026-07-25/ta458-roundpress-webmail-zero-days-sogo-cve-2026-8496 · 2026-07-25/laundry-bear-zimreaper-app-password-persistence · ATT&CK page ↗

Persistence TA0003

T1098Account Manipulation×1

Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.

Evidence: 2026-07-25/laundry-bear-zimreaper-app-password-persistence · ATT&CK page ↗

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-07-25/ta458-roundpress-webmail-zero-days-sogo-cve-2026-8496 · ATT&CK page ↗

Privilege Escalation TA0004

T1098Account Manipulation×1

Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.

Evidence: 2026-07-25/laundry-bear-zimreaper-app-password-persistence · ATT&CK page ↗

Credential Access TA0006

T1539Steal Web Session Cookie×2

An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website.

Evidence: 2026-07-25/ta458-roundpress-webmail-zero-days-sogo-cve-2026-8496 · 2026-07-25/laundry-bear-zimreaper-app-password-persistence · ATT&CK page ↗

Collection TA0009

T1114.002Email Collection: Remote Email Collection×2

Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Adversaries may leverage a user's credentials and interact directly with the Exchange server to acquire information from within a network. Adversaries may also access externally facing Exchange services, Office 365, or Google Workspace to access email using credentials or access tokens. Tools such as MailSniper can be used to automate searches for specific keywords.

Evidence: 2026-07-25/ta458-roundpress-webmail-zero-days-sogo-cve-2026-8496 · 2026-07-25/laundry-bear-zimreaper-app-password-persistence · ATT&CK page ↗

Command and Control TA0011

T1071.004Application Layer Protocol: DNS×1

Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-07-25/laundry-bear-zimreaper-app-password-persistence · ATT&CK page ↗

Story timeline

  1. 2026-07-25TA458 / Operation RoundPress: a running supply of half-click webmail zero-days adds a fresh SOGo flaw (CVE-2026-8496)
    deep-diveGRU-assessed TA458 keeps a live half-click zero-day supply across five self-hosted webmail platforms
  2. 2026-07-25LAUNDRY BEAR's Zimbra zero-click, unpacked: ZimReaper's CSS-@import sanitizer bypass and an app-password that survives a password reset
    updatesProofpoint adds the mechanics the Zimbra joint advisory omitted — including a persistence trick patching doesn't remove

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

uses

Where this entity is cited

  • updates1
  • deep-dive1

Source distribution

  • proofpoint.com2 (40%)
  • cisa.gov1 (20%)
  • github.com1 (20%)
  • welivesecurity.com1 (20%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about TA458 (2)

2026-07-25 · view entry permalink →

HIGHCVE-2026-8496exploitedNATOB2

TA458 / Operation RoundPress: a running supply of half-click webmail zero-days adds a fresh SOGo flaw (CVE-2026-8496)

Background. ESET first documented Operation RoundPress in 2025 as a Russia-aligned campaign abusing cross-site-scripting flaws in self-hosted webmail (initially Roundcube, later broadened) to steal mail from Ukrainian and Eastern-European government targets (ESET Research, 2025-05-15). It sits in a longer lineage of GRU-linked webmail-XSS espionage — the same tradecraft class CERT-UA, ANSSI and multiple vendors have tracked across APT28/Sofacy and WinterVivern operations against Roundcube and Zimbra since 2023. Proofpoint's 2026-07-23 report is the first to consolidate the current actor (which it tracks as TA458) as running a standing supply of such zero-days across five distinct webmail products at once, and to disclose a previously-unknown SOGo flaw within it.

TA458 runs "half-click" exploits: the target "must only open the malicious email in their webmail viewer to be compromised" — no link, attachment, or click (Proofpoint, 2026-07-23). The mechanism is an event-handler injection into content the webmail client fails to sanitize, executing attacker JavaScript in the victim's authenticated session the moment the message renders. The active set spans Zimbra (CVE-2025-27915), mDaemon (CVE-2025-3929), Roundcube (n-day CVE-2023-43770 and CVE-2024-42009), Kerio Connect (a flaw found March 2026, no CVE assigned to the end-of-life product), and — newly disclosed — SOGo, where Proofpoint "reported to the vendor, Alinto; it was patched as CVE-2026-8496 in version 5.12.8" (Proofpoint, 2026-07-23). Each intrusion drops SpyPress, a per-client-customized obfuscated JavaScript payload whose consistent objective across variants is "theft of credentials, contacts, and emails."

On Roundcube targets the operation has shifted from smash-and-grab theft to durable access: SpyPress chains a second Roundcube flaw (CVE-2025-49113) that abuses the file-upload handler to trigger unsafe PHP deserialization, using the mail server's own GPG engine as a deserialization gadget to execute code, then plants PHP webshells inside Roundcube's program and plugin directories and multiple reverse-shell fallbacks (Proofpoint, 2026-07-23). Targeting concentrates on Ukrainian government and Eastern-European military and government entities across Albania, Greece, Moldova and Türkiye, with occasional chemical, telecom and technology victims. Proofpoint "assesses that TA458 is likely a Russian military intelligence operation directed by the Russian GRU" and reports no telemetry overlap between TA458 and TA422 (APT28/Sofacy) — a distinct GRU cluster — with the specific unit unconfirmed. Attribution here is not settled across vendors: ESET's original Operation RoundPress reporting associated the activity with Sednit (APT28), so the TA458 and RoundPress labels should be treated as overlapping tracking rather than a single confirmed actor.

A 'half-click exploit' requires no social engineering, nor does it require a user to click a link or open an attachment. The targeted user must only open the malicious email in their webmail viewer to be compromised.

SOGo webmail platform, which we reported to the vendor, Alinto; it was patched as CVE-2026-8496 in version 5.12.8

Proofpoint assesses that TA458 is likely a Russian military intelligence operation directed by the Russian GRU.

Proofpoint Threat Research 2026-07-23

Builds on: 2026-07-24/laundry-bear-zimbra-zero-click-cve-2025-66376

threat25 Jul 04:38Zmulti-sourceOpen finding ↗

2026-07-25 · view entry permalink →

NOTABLEupdateNATOB2

LAUNDRY BEAR's Zimbra zero-click, unpacked: ZimReaper's CSS-@import sanitizer bypass and an app-password that survives a password reset

UPDATE · originally covered Russian state actor LAUNDRY BEAR weaponised a Zimbra webmail zero-click (CVE-2025-66376) for mailbox exfiltration — now exposed in a 16-nation joint advisory (2026-07-24)

The prior entry covered the 16-nation joint advisory (AA26-204A) on LAUNDRY BEAR's (TA488 / Void Blizzard) zero-click Zimbra campaign exploiting CVE-2025-66376. Proofpoint's own two-part writeup adds mechanics the advisory did not detail (Proofpoint, 2026-07-23).

The exploit defeats Zimbra's client-side HTML sanitizer by tag-splitting: a fake CSS @import directive is fragmented across HTML tags so that the sanitizer strips each @import sequence individually, but "the browser successfully reconstructs <svg onload="eval(atob('…'))"> and executes it" — a sanitizer-bypass-by-reassembly, where the surviving characters rejoin into valid executing script (Proofpoint, 2026-07-23). The resulting payload — which Proofpoint attributes to LAUNDRY BEAR's post-exploitation tooling and names ZimReaper — steals CSRF tokens, browser-autofill credentials, 2FA scratch codes and the Zimbra version/URL, exfiltrating tokens via DNS tunneling (Base32-encoded subdomains carrying a session id and a plaintext token-type label) and mail archives via HTTP POST.

The operationally important delta is persistence: after exploitation ZimReaper issues a CreateAppSpecificPasswordRequest to mint a Zimbra application-specific password labelled "ZimbraWeb" that bypasses 2FA and grants IMAP/POP3/SMTP access, then exfiltrates it via DNS for direct mailbox access (Proofpoint, 2026-07-23). Because that credential is independent of the primary account password, it survives a password reset and the CVE-2025-66376 patch alike.

the sanitizer fails to recognize it as executable markup, while the browser successfully reconstructs <svg onload="eval(atob('…'))"> and executes it.

Proofpoint has not observed TA458 using CVE-2025-66376, despite the group's regular access to webmail XSS zero-days.

Proofpoint Threat Research 2026-07-23

Builds on: 2026-07-25/ta458-roundpress-webmail-zero-days-sogo-cve-2026-8496

threat25 Jul 04:38Zmulti-sourceOpen finding ↗