Skip to content
ta458 roundpress exploits

ta458 roundpress exploits

Proofpoint July 23, 2026

This is part 2 of a 2-part blog series Proofpoint is publishing Russian espionage actors using half-click exploits to target government webmail servers. Read part 1 TA488 here , and the accompanying advisory from NSA here .

Threat Research would like to thank the Proofpoint Cloudmark Authority team.

TA458 is an espionage threat actor with prolific access to “half-click” cross-site scripting (XSS) exploits in webmail software. TA458 is likely aligned with Russia’s General Staff Main Intelligence Directorate (GRU). In March 2026, Proofpoint discovered TA458 exploiting a zero-day vulnerability in the SOGo webmail platform, which we reported to the vendor, Alinto; it was patched as CVE-2026-8496 in version 5.12.8 .

TA458 primarily targets Ukrainian government and Eastern European military and government entities across Albania, Greece, Moldova, and Türkiye, with occasional targeting of chemical, telecommunications, and technology firms. TA458 continues to use SpyPress - an obfuscated JavaScript-based malware seen in Operation RoundPress - which the adversary modifies based on the targeted mailserver.

TA458 expanded its webmail targeting scope since ESET’s Operation RoundPress blog in May 2025. Proofpoint observed additional TA458 targeting of Kerio Webmail and SOGo Webmail, in addition to exploits deployed against Zimbra, mDaemon, and Roundcube. StrikeReady also observed TA458 use CVE-2025-27915 as a zero-day targeting Zimbra webmail servers in a campaign from April 2025. Proofpoint tracks TA458 as distinct from Operation Roundish , which was found by Hunt.io in March 2026 and used longstanding infrastructure that CERT-UA attributed to APT28 in 2024.

TA458 uses a combination of actor-controlled and compromised accounts to send exploit-laden messages. On some occasions, where visible, the threat actor uses proxy services as jump boxes to send the emails onward. Proofpoint has not observed previously targeted mailservers being used to send exploit-laden emails to new targets. It is likely that TA458 procures sending addresses in another manner, in part due to SpyPress malware only being able to set persistent access to the mailserver on mDaemon and Roundcube (see below) targets.

Figure 1. TA458 lure email using compromised sender to target Ukrainian entities in March 2026.

TA458 exploits this class of vulnerability by finding features in webmails that are not properly sanitized, such as event handlers that can be abused to execute arbitrary JavaScript. Proofpoint discovered TA458 exploiting vulnerabilities in Kerio and SOGo webmail platforms in March 2026 and reported our findings to the vendors. The affected Kerio webmail product was old and outdated enough that a CVE was not issued.

Figure 2. SOGo webmail zero-day exploit CVE-2026-8496.

In total, Proofpoint has observed TA458 exploiting the following webmail vulnerabilities:

Since February 2026, the SpyPress malware has used a customized variant of the JavaScript obfuscation tool Obfuscator IO. The malware still varies in capabilities based on the target webmail that it is deployed against. However, the core functionality remains consistent regardless of the target: theft of credentials, contacts, and emails.

Figure 3. Customized Obfuscator IO usage in SpyPress malware.

Since at least July 2025, TA458 began removing stealing components, and swapping in interactive backdoor mechanisms to its Roundcube variant of SpyPress, to enable long-term access to the instance. SpyPress uses a second Roundcube exploit ( CVE-2025-49113 ) that abuses Roundcube's file upload handler to trigger unsafe PHP deserialization. The deserialization allows SpyPress to use Crypt_GPG_Engine as a gadget to attacker-controlled input to the system GPG binary as a config file argument, allowing for arbitrary code execution.

Figure 4. Roundcube deserialization function in SpyPress payload.

SpyPress attempts to install six distinct backdoor or persistence mechanisms with that exploit, which is likely built as a series of fallbacks to ensure the server is able to facilitate at least one of the backdoor methods. These persistence mechanisms are as follows:

Each command that connects to TA458 C&C servers uses a unique URI path, so the operators can understand the context of execution.

Proofpoint assesses that TA458 is likely a Russian military intelligence operation directed by the Russian GRU. At the time of writing, there is no indication of targeting overlap in Proofpoint telemetry between TA458 and TA422 (Sofacy, APT28, Fancy Bear, Forest Blizzard), which has been attributed to GRU Unit 26165 .

In April 2025, France’s cybersecurity agency, ANSSI, published a document providing broad context for TA422 activity targeting France. In conjunction with this publication, France’s Ministry for Europe and Foreign Affairs published a press release that highlighted an additional GRU unit, 20728. It is plausible that TA458 is linked to Unit 20728 based on the distinct TTPs and targeting of the two clusters in our data, and the French government naming an otherwise unknown unit in its press release. Proofpoint lacks data to substantiate this hypothesis at the time of writing; however, there is a possibility of attribution to a GRU unit other than 26165.

Proofpoint has observed TA458 continue to target government entities in Ukraine, as well as military and government installations in Eastern Europe, with targets in Albania, Greece, Moldova, and Türkiye. There has also been outlier targeting of chemical entities, telecommunications, and technology companies. It is unclear whether TA458 acquires new exploit capabilities after identifying targets running a particular webmail platform, or whether availability informs targeting decisions.

While TA458 appears to be a capable adversary from the activity described, there have been multiple instances where there was no reconnaissance of the targeted users or where exploit emails were sent to entities not running the targeted webmail server.

The use of large language models (LLMs) will likely accelerate TA458’s vulnerability discovery rate in the very short term (along with other actors using this vector). However, as these webmail providers benefit from a correlative ability to find and close bugs in their code base, the half-click vector will likely lose its overall effectiveness as the webmail providers reduce the available attack surface in the long term. TA458 will likely continue to find more obscure webmail providers to target following this shift, but eventually switch tactics to target the mailboxes as these exploitation vectors are closed.

2071250 - ET MALWARE JS SpyPress C2 Beacon

2071251 - ET MALWARE JS SpyPress C2 Success Callback (PHP)

2071252 - ET MALWARE JS SpyPress C2 Success Callback (Python)

2071253 - ET MALWARE JS SpyPress C2 Success Callback (cURL)

2071254 - ET MALWARE JS SpyPress Dropped Webshell Inbound Request (list.js.php)

2071255 - ET MALWARE JS SpyPress Dropped Webshell Inbound Request (blank.gif.php)

2071256 - ET MALWARE JS SpyPress Dropped Webshell Inbound Request (password.js.php)

2071257 - ET MALWARE JS SpyPress Dropped Webshell Inbound Request (get.php.php)

2868022 - ETPRO EXPLOIT Alinto SOGo Webmail Cross-Site Scripting via .ics Calendar Invite (CVE-2026-8496)

2865231 - ETPRO WEB_SERVER Zimbra Collaboration (ZCS) Suite Cross-site Scripting (CVE-2025-27915)

2865595 - ETPRO EXPLOIT MDaemon Email Server XSS via img Tag (CVE-2025-3929)

2051827 - ET EXPLOIT RoundCube Webmail Persistent XSS Attempt (CVE-2023-43770)

2066621 - ET WEB_SPECIFIC_APPS Roundcube Webmail Cross-Site Scripting (CVE-2024-42009)

2867176 - ETPRO WEB_SPECIFIC_APPS Roundcube Webmail Cross-Site Scripting M2 (CVE-2024-42009)

2063428 - ET WEB_SPECIFIC_APPS Roundcube Post-Auth RCE via PHP Object Deserialization (CVE-2025-49113)

625e4c166c7a1d5a1becf56b27d4f76a2f95935cbd8d556c30a493263d10dbf8

Exploit-laden email (CVE-2023-43770 - Roundcube)

a0c80cab70d6672b01710a70f93311fc1c1db2fbbf9cd6daa543c34b87e3444a

Exploit-laden email (CVE-2025-27915 - Zimbra)

fb8ec4dbed14c0a91361abd82ebe9fb083615c3dbb15348f57317af7cc41dd34

Exploit-laden email (CVE-2025-27915 - Zimbra)

3a449148a0e3cac604fb93210dd7d91ccf48e06ed9aae064bc53a419a84ce9ba

Exploit-laden email (CVE-2024-42009 - Roundcube)

8b5a4dc237a4c89042176bc89864a4c357dcdd14fa544fe6496ccb6c31cd5b7f

Exploit-laden email (CVE-2025-3929 - mDaemon)

6b2c02bf82087a3ca5fb7ef8046554ff29ce85d52202bdcfae2b2653aede139a

Exploit-laden email (CVE-2024-42900 + CVE-2025-49113 - Roundcube)

e27d1bf82249002a66395c89dbda6ec5d8df012a84b79d36fffbbf7808d28878

Exploit-laden email (CVE-2026- 8496, SOGo)