Executive Summary
Proofpoint has identified ongoing activity by TA458 (likely aligned with Russia's GRU) targeting government and military entities in Ukraine and Eastern Europe. This campaign, part of Operation RoundPress, leverages "half-click" exploits—vulnerabilities that require only that a user open a malicious email in a webmail viewer to trigger execution without clicking any links or attachments.
Technically, the actor utilizes a sophisticated exploit supply chain targeting platforms like SOGo (CVE-2026-8496), Zimbra (CVE-2025-27915), and Roundcube. The primary tool, SpyPress, is an obfuscated JavaScript malware designed to exfiltrate credentials, contacts, and emails. In recent iterations, TA458 has evolved to include interactive backdoors and persistence mechanisms on Roundcube servers by abusing unsafe PHP deserialization (CVE-2025-49113).
This threat is critical for government, defense, and essential service providers in Europe. The adversary remains undeterred by public exposure and continues to demonstrate access to functional zero-day exploits, making patching and monitoring of public-facing webmail instances a priority.
