Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days

hgmydr.wiki

TLP:CLEAR
Active

Domain

Description

TA458, a Russia-aligned espionage group likely linked to GRU, continues exploiting half-click cross-site scripting vulnerabilities in webmail platforms to steal sensitive email data. These exploits require no user interaction beyond opening the malicious email in webmail. The actor exploited multiple zero-days including SOGo (CVE-2026-8496), Zimbra (CVE-2025-27915), and mDaemon (CVE-2025-3929), alongside n-day Roundcube vulnerabilities. TA458 deploys SpyPress malware, an obfuscated JavaScript-based tool customized for each targeted mailserver, stealing credentials, contacts, and emails. The group primarily targets Ukrainian government entities and Eastern European military installations across Albania, Greece, Moldova, and Türkiye, with occasional focus on chemical, telecommunications, and technology sectors. Recent variants include backdoor mechanisms for persistent access through reverse shells and webshells.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days
Pattern Type
STIX
Confidence
75%
Valid From
Jul 24, 2026 02:00
Total Sightings
0
Added
Jul 24, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of hgmydr.wiki

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.