Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days
released on 2026-07-23 @ 04:30:34 PM
TA458, a Russia-aligned espionage group likely linked to GRU, continues exploiting half-click cross-site scripting vulnerabilities in webmail platforms to steal sensitive email data. These exploits require no user interaction beyond opening the malicious email in webmail. The actor exploited multiple zero-days including SOGo (CVE-2026-8496), Zimbra (CVE-2025-27915), and mDaemon (CVE-2025-3929), alongside n-day Roundcube vulnerabilities. TA458 deploys SpyPress malware, an obfuscated JavaScript-based tool customized for each targeted mailserver, stealing credentials, contacts, and emails. The group primarily targets Ukrainian government entities and Eastern European military installations across Albania, Greece, Moldova, and Türkiye, with occasional focus on chemical, telecommunications, and technology sectors. Recent variants include backdoor mechanisms for persistent access through reverse shells and webshells.