2026-07-25 · view entry permalink →
TA458 / Operation RoundPress: a running supply of half-click webmail zero-days adds a fresh SOGo flaw (CVE-2026-8496)
Background. ESET first documented Operation RoundPress in 2025 as a Russia-aligned campaign abusing cross-site-scripting flaws in self-hosted webmail (initially Roundcube, later broadened) to steal mail from Ukrainian and Eastern-European government targets (ESET Research, 2025-05-15). It sits in a longer lineage of GRU-linked webmail-XSS espionage — the same tradecraft class CERT-UA, ANSSI and multiple vendors have tracked across APT28/Sofacy and WinterVivern operations against Roundcube and Zimbra since 2023. Proofpoint's 2026-07-23 report is the first to consolidate the current actor (which it tracks as TA458) as running a standing supply of such zero-days across five distinct webmail products at once, and to disclose a previously-unknown SOGo flaw within it.
TA458 runs "half-click" exploits: the target "must only open the malicious email in their webmail viewer to be compromised" — no link, attachment, or click (Proofpoint, 2026-07-23). The mechanism is an event-handler injection into content the webmail client fails to sanitize, executing attacker JavaScript in the victim's authenticated session the moment the message renders. The active set spans Zimbra (CVE-2025-27915), mDaemon (CVE-2025-3929), Roundcube (n-day CVE-2023-43770 and CVE-2024-42009), Kerio Connect (a flaw found March 2026, no CVE assigned to the end-of-life product), and — newly disclosed — SOGo, where Proofpoint "reported to the vendor, Alinto; it was patched as CVE-2026-8496 in version 5.12.8" (Proofpoint, 2026-07-23). Each intrusion drops SpyPress, a per-client-customized obfuscated JavaScript payload whose consistent objective across variants is "theft of credentials, contacts, and emails."
On Roundcube targets the operation has shifted from smash-and-grab theft to durable access: SpyPress chains a second Roundcube flaw (CVE-2025-49113) that abuses the file-upload handler to trigger unsafe PHP deserialization, using the mail server's own GPG engine as a deserialization gadget to execute code, then plants PHP webshells inside Roundcube's program and plugin directories and multiple reverse-shell fallbacks (Proofpoint, 2026-07-23). Targeting concentrates on Ukrainian government and Eastern-European military and government entities across Albania, Greece, Moldova and Türkiye, with occasional chemical, telecom and technology victims. Proofpoint "assesses that TA458 is likely a Russian military intelligence operation directed by the Russian GRU" and reports no telemetry overlap between TA458 and TA422 (APT28/Sofacy) — a distinct GRU cluster — with the specific unit unconfirmed. Attribution here is not settled across vendors: ESET's original Operation RoundPress reporting associated the activity with Sednit (APT28), so the TA458 and RoundPress labels should be treated as overlapping tracking rather than a single confirmed actor.
A 'half-click exploit' requires no social engineering, nor does it require a user to click a link or open an attachment. The targeted user must only open the malicious email in their webmail viewer to be compromised.
SOGo webmail platform, which we reported to the vendor, Alinto; it was patched as CVE-2026-8496 in version 5.12.8
Proofpoint assesses that TA458 is likely a Russian military intelligence operation directed by the Russian GRU.
Builds on: 2026-07-24/laundry-bear-zimbra-zero-click-cve-2025-66376