Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: tracked as, Taxol

Description

TA458 (Taxol/ RoundPress) has evolved into a highly sophisticated adversary that focuses on exploiting webmail platforms through zero- or half-click techniques. The group weaponizes newly disclosed cross-site scripting (XSS) vulnerabilities—such as CVE‑2025‑66376 and CVE‑2026‑8496—in popular mail suites (Roundcube, Zimbra, mDaemon, SOGo, Kerio), enabling the delivery of obfuscated JavaScript payloads by simply opening a malicious email. At deployment, the core malware—SpyPress—is tailored for each target; it harvests user credentials including app‑specific passwords, auto-fill tokens and two-factor scratch codes, and pulls entire address books for later use. Persistence is achieved through multiple mechanisms: creation of privileged accounts, installation of service-based backdoors (PortDoor, nccTrojan), DLL hijacking, process hollowing, and scheduled tasks. Post‑exploitation, TA458 relies heavily on covert DNS exfiltration over Base32 or TLS‑SNI payloads, as well as HTTP POST of compressed archives to staging servers. The actor also deploys legitimate remote-access utilities such as DWAgent, custom proxy tools, and PowerShell scripts to facilitate lateral movement and sustain long-term access. In addition to webmail exploitation, TA458 has executed spearphishing attachments that exploit older Word CVEs (e.g., CVE‑2017‑11882) to deliver backdoors. The group targets high-profile state entities in Ukraine, Greece, Albania, Moldova, and neighboring regions within the telecommunications, defense, and critical infrastructure sectors. TA458’s operational tempo appears continuous; new exploits are published as soon as they are identified. While the supply chain remains unclear—either internally or via third‑party developers—the actor consistently blends webmail abuse, credential theft, and stealthy persistence techniques to achieve its espionage objectives.

Goals & Targeting

Targeted Sectors

Government
Defense
Communications
Telecommunications
Education
Utilities
Critical infrastructure
Chemical
Nuclear
Energy
Manufacturing
Financial services
Non profit
Information technology

Targeted Countries / Regions

Albania
Greece
Moldova, Republic of
Ukraine
US
RU
UA
CN
IR
RO
BR
BY
FR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 52 minutes ago

Executive Summary

TA458, also known as Taxol or RoundPress, is a sophisticated threat actor that primarily targets government and critical‑infrastructure entities in Eastern Europe through zero- or half-click webmail exploitation. By leveraging recent CVEs in popular mail platforms, delivering obfuscated JavaScript payloads such as SpyPress, and maintaining persistence via backdoors and system manipulation, the group continuously exfiltrates credentials and sensitive data. The actor combines credential theft, covert DNS exfiltration, legitimate remote access tools, and lateral movement techniques to maintain long‑term presence within target networks. Its operations demonstrate a clear espionage motive aimed at extracting strategic information from high‑profile state targets.

Goals & Targeting

The primary strategic objective of TA458 is state-sponsored intelligence gathering with a focus on government, defense, telecommunications, energy, and critical infrastructure organizations. By extracting credentials, contact lists, and sensitive email content, the actor seeks to build extensive adversary maps for future intrusion campaigns. The targeting profile demonstrates a preference for high‑profile state institutions in Eastern Europe—Ukraine, Greece, Albania, Moldova—as well as neighboring regions where diplomatic or intelligence value is high. TA458’s use of advanced exfiltration channels and persistent backdoors indicates an intent for long-term data collection rather than sporadic attacks.

Enhanced Description

Key Capabilities

  • Exploiting webmail XSS/zero‑click vulnerabilities (e.g., CVE-2025-66376, CVE-2026-8496) to deliver payloads
  • Deploying obfuscated JavaScript malware (SpyPress) for credential and contact book theft
  • Establishing persistence via privileged account creation, service‑based backdoors (PortDoor, nccTrojan), DLL hijacking, process hollowing, scheduled tasks
  • Covert DNS exfiltration using Base32 or TLS‑SNI, HTTP POST of compressed archives to staging servers
  • Utilizing legitimate remote‑access tools such as DWAgent for lateral movement and persistence
  • Leveraging PowerShell scripts for execution and expansion
  • Using PHP object deserialization gadget (Crypt_GPG_Engine) for arbitrary code execution
  • Executing spearphishing attachments exploiting old Word CVEs (CVE-2017-11882)
  • Custom proxy utilities to route attack traffic
  • Deploying unique URI paths for C&C communication

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Credential Access
Discovery
Lateral Movement
Command & Control

ATT&CK Techniques

T1003
T1018
T1021.006
T1036.005
T1036.008
T1053.005
T1068
T1070.004
T1070.006
T1074
T1078.002
T1087.002
T1101?
T1112
T1114
T1125?
T1132.001
T1140
T127?
T1583.001
T1583.002
T1505.003
T1564.002
T1556.008
T1041
T1059.001
T1069?
T1071.004

Software / Tooling

SpyPress
DWAgent
PortDoor
nccTrojan
Crypt_GPG_Engine

Campaigns & Victims

TA458 demonstrates a continuous operational approach, rapidly introducing new exploits as vulnerabilities are disclosed. The actor’s pattern centers on attacking state and critical infrastructure entities in Ukraine and surrounding Eastern European countries with high-value intel. Webmail exploitation remains the primary entry vector, delivering stealthy JavaScript backdoors that establish persistent footholds through privileged accounts and system-level persistence mechanisms. Once inside, TA458 uses DNS covert channels for data exfiltration and supplements this with HTTP-based staging of compressed archives. The use of legitimate remote‑access tools and PowerShell scripts facilitates lateral expansion across victim networks, while spearphishing attachments provide alternative delivery methods to reach a diversity of targets.

IOC Patterns

  • Vulnerability exploitation via XSS or PHP deserialization (e.g., CVE-2025-66376, CVE-2026-8496)
  • Half‑click webmail exploitation vectors that deliver JavaScript payloads
  • Covert DNS query patterns used for command-and-control and exfiltration
  • Obfuscated JavaScript attachments in emails

Recommended Actions

  • Patch all affected webmail platforms (Roundcube, Zimbra, mDaemon, SOGo, Kerio) for known CVEs immediately.
  • Deploy email security solutions that detect and block exploit-laden emails and suspicious obfuscated JavaScript payloads.
  • Implement multi‑factor authentication on all mail accounts to reduce credential theft impact.
  • Monitor DNS traffic for anomalous queries indicative of covert exfiltration or C2 channels.
  • Restrict or audit the use of legitimate remote-access tools (e.g., DWAgent) within the enterprise perimeter.
  • Harden PHP configurations to disable object deserialization where possible and deploy Web Application Firewalls to block malicious payload uploads.
  • Track outbound HTTP requests for unusual URI patterns that may signal SpyPress or other backdoors.
  • Conduct proactive threat hunting focusing on known CVE exploitation indicators in mail logs and DNS traffic.
  • Ensure Windows systems are updated to mitigate DLL hijacking, process hollowing, scheduled-task persistence techniques.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 4 Domain 11 Filename 4 MD5 Hash 1

References

  1. https://www.cuinfosecurity.com/russian-espionage-hackers-hit-zimbra-half-click-attacks-a-32322 — Cited by AI analysis.
  2. https://risky.biz/risky-bulletin-western-cyber-agencies-warn-of-russian-hacks-of-zimbra-servers/ — Cited by AI analysis.
  3. https://thisweekin4n6.com/2026/07/26/week-30-2026/ — Cited by AI analysis.
  4. https://wokb.cz/index.html — Cited by AI analysis.
  5. https://mallory.ai/actors/019f8f97-508b-7d72-ba2b-e65609835481 — Cited by AI analysis.
  6. https://thehackernews.com/2026/07/fake-notepad-plugin-delivers.html — Cited by AI analysis.
  7. https://ics-cert.kaspersky.com/publications/targeted-attack-on-industrial-enterprises-and-public-institutions/ — Cited by AI analysis.
  8. https://www.stamus-networks.com/stamus-labs/detection-update-2024-12-17 — Cited by AI analysis.
  9. https://malpedia.caad.fkie.fraunhofer.de/actor/ta428 — Cited by AI analysis.
  10. https://unit42.paloaltonetworks.com/new-toolset-targets-middle-east-africa-usa/ — Cited by AI analysis.
  11. https://mallory.ai/stories/019f8f88-885d-713b-a42c-ba7206f212a4 — Cited by AI analysis.
  12. https://mallory.ai/stories/019f8f88-6228-790a-994a-d7f38afaac62 — Cited by AI analysis.
  13. https://www.technadu.com/zimbra-half-click-webmail-zero-day-exploited-by-russian-spies-to-steal-emails-credentials/631858/ — Cited by AI analysis.
  14. https://cyfar.ca/ — Cited by AI analysis.
  15. https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits — Cited by AI analysis.
  16. https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits — Cited by AI analysis.
  17. https://www.sec-ttl.com/russian-zimbra-zero-click-exploit-emails-2fa-codes/ — Cited by AI analysis.
  18. https://yandex.com/?text=ta458 — Cited by AI analysis.

Intel Summary

38

Techniques

55

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

APT
Russia-aligned
Government Espionage
Cyber Intelligence
Eastern Europe
Russian
GRU-linked
State-sponsored
Webmail exploit
Zimbra
Half‑Click exploitation
Operation RoundPress
Zero-Day
Credential Access
Email Harvesting
SpyPress malware
DNS Exfiltration
XSS
TA458
Ukraine Targeting
Government
Defense
Communications

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
United States (US)
Confidence
55%
Added
Jul 24, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.