---
schema: 1
kind: threat
title: "TA458 / Operation RoundPress: a running supply of half-click webmail zero-days adds a fresh SOGo flaw (CVE-2026-8496)"
headline: "GRU-assessed TA458 keeps a live half-click zero-day supply across five self-hosted webmail platforms"
summary: >
  Proofpoint details TA458 (ESET's Operation RoundPress), a GRU-assessed Russian espionage actor running a
  standing supply of "half-click" webmail zero-days that fire the instant a target opens a message. The current
  set spans Zimbra, mDaemon, Roundcube, Kerio and — newly disclosed — SOGo (zero-day CVE-2026-8496, patched in
  5.12.8), each dropping the per-client SpyPress payload to steal credentials, contacts and mail. Any
  internet-reachable self-hosted webmail in EU/CH public-sector estates is standing exposure.
discovered_at: "2026-07-25T04:38:26Z"
event_date: "2026-07-23"
run_id: 2026-07-25T0409Z-intel
priority: high
immediate_action: null
tags: [nation-state, espionage, russia-nexus, zero-day, zero-click, phishing, identity]
regions: [europe, global]
sectors: [public-sector, telco, technology, defense]
entities: [actor:ta458-roundpress, malware:spypress]
techniques: [T1566, T1203, T1190, T1539, T1114.002, T1505.003]
affected_products: ["Zimbra Collaboration Suite", "MDaemon Email Server", "Roundcube Webmail", "Kerio Connect", "SOGo"]
cves:
  - id: CVE-2026-8496
    cvss: null
    epss: null
    type: xss
    vector: zero-click
    auth: pre-auth
    status: [exploited, patch-available]
    affected: "SOGo prior to 5.12.8"
    fixed: "5.12.8"
sources:
  - url: "https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits"
    publisher: "Proofpoint Threat Research"
    date: "2026-07-23"
    role: primary
  - url: "https://www.welivesecurity.com/en/eset-research/operation-roundpress/"
    publisher: "ESET Research"
    date: "2025-05-15"
    role: corroborating
  - url: "https://github.com/Alinto/sogo/releases/tag/SOGo-5.12.8"
    publisher: "Alinto (SOGo release notes)"
    date: "2026-05-12"
    role: corroborating
closed_sources: []
evidence:
  - quote: "A 'half-click exploit' requires no social engineering, nor does it require a user to click a link or open an attachment. The targeted user must only open the malicious email in their webmail viewer to be compromised."
    publisher: "Proofpoint Threat Research"
  - quote: "SOGo webmail platform, which we reported to the vendor, Alinto; it was patched as CVE-2026-8496 in version 5.12.8"
    publisher: "Proofpoint Threat Research"
  - quote: "Proofpoint assesses that TA458 is likely a Russian military intelligence operation directed by the Russian GRU."
    publisher: "Proofpoint Threat Research"
verification: multi-source
sourcing_note: "The new SOGo zero-day CVE-2026-8496 and the current five-platform campaign specifics are Proofpoint's own single-vendor disclosure (the SOGo patch is corroborated by the Alinto 5.12.8 release). Attribution is not settled: ESET's original Operation RoundPress reporting associated the activity with Sednit (APT28), whereas Proofpoint tracks the current actor as TA458 and reports no telemetry overlap with TA422 (APT28) — so the names are not a clean equivalence, and the specific GRU unit is unconfirmed."
confidence: high
update_of: null
references: [2026-07-24/laundry-bear-zimbra-zero-click-cve-2025-66376]
deep_dive: true
deep_dive_category: apt-campaign
org_triage: null
classification:
  reliability: B
  credibility: 2
watchlist_hit: false
actions:
  - "Patch every self-hosted SOGo instance to 5.12.8 now — CVE-2026-8496 is a webmail zero-day being used by TA458 to fire on message-open with no user interaction."
  - "Inventory internet-reachable self-hosted Zimbra, mDaemon, Roundcube, Kerio and SOGo webmail and prioritise those instances for patching — with a half-click exploit, an exposed unpatched webmail server equals mailbox-compromise-on-view."
migrated_from: null
---

**Background.** ESET first documented Operation RoundPress in 2025 as a Russia-aligned campaign abusing cross-site-scripting flaws in self-hosted webmail (initially Roundcube, later broadened) to steal mail from Ukrainian and Eastern-European government targets ([ESET Research, 2025-05-15](https://www.welivesecurity.com/en/eset-research/operation-roundpress/)). It sits in a longer lineage of GRU-linked webmail-XSS espionage — the same tradecraft class CERT-UA, ANSSI and multiple vendors have tracked across APT28/Sofacy and WinterVivern operations against Roundcube and Zimbra since 2023. Proofpoint's 2026-07-23 report is the first to consolidate the current actor (which it tracks as TA458) as running a *standing supply* of such zero-days across five distinct webmail products at once, and to disclose a previously-unknown SOGo flaw within it.

TA458 runs "half-click" exploits: the target "must only open the malicious email in their webmail viewer to be compromised" — no link, attachment, or click ([Proofpoint, 2026-07-23](https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits)). The mechanism is an event-handler injection into content the webmail client fails to sanitize, executing attacker JavaScript in the victim's authenticated session the moment the message renders. The active set spans Zimbra (CVE-2025-27915), mDaemon (CVE-2025-3929), Roundcube (n-day CVE-2023-43770 and CVE-2024-42009), Kerio Connect (a flaw found March 2026, no CVE assigned to the end-of-life product), and — newly disclosed — SOGo, where Proofpoint "reported to the vendor, Alinto; it was patched as CVE-2026-8496 in version 5.12.8" ([Proofpoint, 2026-07-23](https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits)). Each intrusion drops SpyPress, a per-client-customized obfuscated JavaScript payload whose consistent objective across variants is "theft of credentials, contacts, and emails."

On Roundcube targets the operation has shifted from smash-and-grab theft to durable access: SpyPress chains a second Roundcube flaw (CVE-2025-49113) that abuses the file-upload handler to trigger unsafe PHP deserialization, using the mail server's own GPG engine as a deserialization gadget to execute code, then plants PHP webshells inside Roundcube's program and plugin directories and multiple reverse-shell fallbacks ([Proofpoint, 2026-07-23](https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits)). Targeting concentrates on Ukrainian government and Eastern-European military and government entities across Albania, Greece, Moldova and Türkiye, with occasional chemical, telecom and technology victims. Proofpoint "assesses that TA458 is likely a Russian military intelligence operation directed by the Russian GRU" and reports no telemetry overlap between TA458 and TA422 (APT28/Sofacy) — a distinct GRU cluster — with the specific unit unconfirmed. Attribution here is not settled across vendors: ESET's original Operation RoundPress reporting associated the activity with Sednit (APT28), so the TA458 and RoundPress labels should be treated as overlapping tracking rather than a single confirmed actor.

**Defender takeaway:** self-hosted webmail is the exposure — a single unpatched Zimbra/Roundcube/SOGo/mDaemon/Kerio server reachable from the internet is a full mailbox-compromise-on-view risk, and the actor rotates zero-days faster than a routine patch cadence closes them. This is the same self-hosted-webmail-zero-click threat surface as the separately-tracked LAUNDRY BEAR/TA488 Zimbra campaign (see references), but a different actor and a broader platform set. **Triage:** the durable telemetry signal is server-side, not host-based — in webmail application and WAF logs, hunt requests to the message-render endpoint carrying HTML with split or obfuscated event-handler / CSS-directive fragments that reassemble into script, and (Roundcube specifically) file-upload-handler POSTs immediately followed by anomalous PHP object-deserialization errors or new script files appearing under the webmail install tree; benign webmail rendering produces neither. Harden by tightening the client-side HTML sanitizer / disabling unauthenticated rich rendering where the product allows it, and treat any external-facing self-hosted webmail as requiring compensating WAF coverage between patch cycles.
