APT28 Exploits Roundcube Vulnerabilities in Targeted Cyber Espionage Campaign

APT28 Exploits Roundcube Vulnerabilities in Targeted Cyber Espionage Campaign

First seen 23 Jul 2026, 14:54 UTC www.welivesecurity.comhunt.io 72% similarity 75.8

Article Content

Browse articles
ThreatCluster

APT28 (Fancy Bear) has been linked to Operation Roundish, utilizing a comprehensive Roundcube exploitation toolkit against Ukrainian government targets. The toolkit, discovered in January 2026, includes XSS payloads, a command-and-control server, and various credential harvesting tools. The operation is part of a broader trend of cyberattacks targeting webmail platforms, particularly in the context of the ongoing conflict in Ukraine. The toolkit supports multiple attack vectors, including persistent mail forwarding and 2FA secret extraction. Additionally, the group has been associated with previous operations like RoundPress, which also targeted webmail vulnerabilities. The exploitation of CVE-2023-43770 has been confirmed, highlighting the group's ongoing focus on exploiting critical vulnerabilities. The attack's scope extends across eleven countries, primarily affecting government and financial sectors.

Key Points: • APT28's Operation Roundish targets Ukrainian government entities using a sophisticated toolkit. • The toolkit includes XSS payloads and credential harvesting capabilities, enhancing operational effectiveness. • The campaign exploits multiple vulnerabilities, including CVE-2023-43770, indicating a persistent threat.

ThreatCluster AI

Timeline

2020-12-28
CVE-2020-35730 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-03-14
CVE-2023-23397 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-09-22
CVE-2023-43770 published
A new XSS vulnerability in Roundcube was disclosed, later exploited by APT28 in their campaigns.
N/A
2023-10-18
CVE-2023-5631 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-02-12
CVE-2023-43770 added to CISA KEV
CISA listed CVE-2023-43770 as actively exploited, raising awareness of its critical nature.
N/A
2024-08-12
CVE-2024-27443 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-11-15
CVE-2024-11182 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-01-01
Roundcube exploitation toolkit discovered
An exposed open directory revealed a complete Roundcube exploitation toolkit linked to APT28 targeting Ukrainian government entities.
hunt.io
2026-07-23
APT28's ongoing operations reported
Recent reports confirm APT28's continued exploitation of Roundcube vulnerabilities, affecting multiple sectors.
welivesecurity.com

Community

Browse all →