Also known as: tracked as, Taxol
TA458 (Taxol/ RoundPress) has evolved into a highly sophisticated adversary that focuses on exploiting webmail platforms through zero- or half-click techniques. The group weaponizes newly disclosed cross-site scripting (XSS) vulnerabilities—such as CVE‑2025‑66376 and CVE‑2026‑8496—in popular mail suites (Roundcube, Zimbra, mDaemon, SOGo, Kerio), enabling the delivery of obfuscated JavaScript payloads by simply opening a malicious email. At deployment, the core malware—SpyPress—is tailored for each target; it harvests user credentials including app‑specific passwords, auto-fill tokens and two-factor scratch codes, and pulls entire address books for later use. Persistence is achieved through multiple mechanisms: creation of privileged accounts, installation of service-based backdoors (PortDoor, nccTrojan), DLL hijacking, process hollowing, and scheduled tasks. Post‑exploitation, TA458 relies heavily on covert DNS exfiltration over Base32 or TLS‑SNI payloads, as well as HTTP POST of compressed archives to staging servers. The actor also deploys legitimate remote-access utilities such as DWAgent, custom proxy tools, and PowerShell scripts to facilitate lateral movement and sustain long-term access. In addition to webmail exploitation, TA458 has executed spearphishing attachments that exploit older Word CVEs (e.g., CVE‑2017‑11882) to deliver backdoors. The group targets high-profile state entities in Ukraine, Greece, Albania, Moldova, and neighboring regions within the telecommunications, defense, and critical infrastructure sectors. TA458’s operational tempo appears continuous; new exploits are published as soon as they are identified. While the supply chain remains unclear—either internally or via third‑party developers—the actor consistently blends webmail abuse, credential theft, and stealthy persistence techniques to achieve its espionage objectives.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
TA458, also known as Taxol or RoundPress, is a sophisticated threat actor that primarily targets government and critical‑infrastructure entities in Eastern Europe through zero- or half-click webmail exploitation. By leveraging recent CVEs in popular mail platforms, delivering obfuscated JavaScript payloads such as SpyPress, and maintaining persistence via backdoors and system manipulation, the group continuously exfiltrates credentials and sensitive data. The actor combines credential theft, covert DNS exfiltration, legitimate remote access tools, and lateral movement techniques to maintain long‑term presence within target networks. Its operations demonstrate a clear espionage motive aimed at extracting strategic information from high‑profile state targets.
Goals & Targeting
The primary strategic objective of TA458 is state-sponsored intelligence gathering with a focus on government, defense, telecommunications, energy, and critical infrastructure organizations. By extracting credentials, contact lists, and sensitive email content, the actor seeks to build extensive adversary maps for future intrusion campaigns. The targeting profile demonstrates a preference for high‑profile state institutions in Eastern Europe—Ukraine, Greece, Albania, Moldova—as well as neighboring regions where diplomatic or intelligence value is high. TA458’s use of advanced exfiltration channels and persistent backdoors indicates an intent for long-term data collection rather than sporadic attacks.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TA458 demonstrates a continuous operational approach, rapidly introducing new exploits as vulnerabilities are disclosed. The actor’s pattern centers on attacking state and critical infrastructure entities in Ukraine and surrounding Eastern European countries with high-value intel. Webmail exploitation remains the primary entry vector, delivering stealthy JavaScript backdoors that establish persistent footholds through privileged accounts and system-level persistence mechanisms. Once inside, TA458 uses DNS covert channels for data exfiltration and supplements this with HTTP-based staging of compressed archives. The use of legitimate remote‑access tools and PowerShell scripts facilitates lateral expansion across victim networks, while spearphishing attachments provide alternative delivery methods to reach a diversity of targets.
IOC Patterns
Recommended Actions
No campaigns linked yet.
No observed data linked yet.
38
Techniques
55
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics