TA458 Operation RoundPress Webmail Zero-Day Campaigns
Score: 9/10

TA458 Operation RoundPress Webmail Zero-Day Campaigns

The Russia-aligned actor TA458 uses half-click XSS zero-day exploits against SOGo, Zimbra, and Roundcube webmail to deploy SpyPress malware and steal sensitive government data.

Executive Summary

Proofpoint has identified ongoing activity by TA458 (likely aligned with Russia's GRU) targeting government and military entities in Ukraine and Eastern Europe. This campaign, part of Operation RoundPress, leverages "half-click" exploits—vulnerabilities that require only that a user open a malicious email in a webmail viewer to trigger execution without clicking any links or attachments.

Technically, the actor utilizes a sophisticated exploit supply chain targeting platforms like SOGo (CVE-2026-8496), Zimbra (CVE-2025-27915), and Roundcube. The primary tool, SpyPress, is an obfuscated JavaScript malware designed to exfiltrate credentials, contacts, and emails. In recent iterations, TA458 has evolved to include interactive backdoors and persistence mechanisms on Roundcube servers by abusing unsafe PHP deserialization (CVE-2025-49113).

This threat is critical for government, defense, and essential service providers in Europe. The adversary remains undeterred by public exposure and continues to demonstrate access to functional zero-day exploits, making patching and monitoring of public-facing webmail instances a priority.

Key Details

Threat Name

TA458 SpyPress Campaign

Affects

SOGo webmail platform, Zimbra webmail servers, mDaemon, Roundcube

Adversary

TA458 Other Adversaries and Aliases: TA488; APT28; TA422

Malware/Tools

SpyPress

Report Score

9out of 10
Quality Score
Excellent
IOC Quality8
TTP Details9
Detection Guidance9
Enterprise Relevance9
Clarity & Structure8
Technical Depth8

Sources