www.welivesecurity.com
APT28 Exploits Roundcube Vulnerabilities in Targeted Cyber Espionage Campaign
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
APT28 (Fancy Bear) has been linked to Operation Roundish, utilizing a comprehensive Roundcube exploitation toolkit against Ukrainian government targets. The toolkit, discovered in January 2026, includes XSS payloads, a command-and-control server, and various credential harvesting tools. The operation is part of a broader trend of cyberattacks targeting webmail platforms, particularly in the context of the ongoing conflict in Ukraine. The toolkit supports multiple attack vectors, including persistent mail forwarding and 2FA secret extraction. Additionally, the group has been associated with previous operations like RoundPress, which also targeted webmail vulnerabilities. The exploitation of CVE-2023-43770 has been confirmed, highlighting the group's ongoing focus on exploiting critical vulnerabilities. The attack's scope extends across eleven countries, primarily affecting government and financial sectors.
Key Points: • APT28's Operation Roundish targets Ukrainian government entities using a sophisticated toolkit. • The toolkit includes XSS payloads and credential harvesting capabilities, enhancing operational effectiveness. • The campaign exploits multiple vulnerabilities, including CVE-2023-43770, indicating a persistent threat.