Espionage group uses webmail server zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-35730 | Cross-Site Scripting in Roundcube Webmail Plain-Text Email Link Handling Roundcube Webmail contains a cross-site scripting (XSS) flaw (CWE-79) in the link-reference handling of rcube_string_replacer.php, where the linkref_addindex function mishandles JavaScript embedded in a link element of a plain-text email. An attacker triggers the flaw simply by sending a crafted plain-text message to a victim; when the message is processed/displayed in the Roundcube interface, the embedded script executes in the context of the victim's webmail session. Successful exploitation can lead to session hijacking, theft of webmail cookies or credentials, and arbitrary actions in the victim's mailbox. Any deployment of Roundcube Webmail is affected, which includes self-hosted instances and webmail offered by hosting providers, ISPs, and universities. Although no public proof-of-concept is known, CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2023-06-22, confirming exploitation in the wild; ransomware association is unknown, and no CVSS score is yet available, though EPSS puts 30-day exploitation probability at 32.7% (98th percentile). Do: Apply the vendor's updated Roundcube release per CISA's required action (updates per vendor instructions); since no specific fixed versions appear in this data, install the latest patched release of your deployed 1.x branch and verify with the vendor advisory. Check webmail servers for processing of plain-text messages with link-reference elements and review logs for anomalous webmail sessions; treat KEV-listed status as evidence of active exploitation and prioritize internet-exposed Roundcube instances. | 6.1 | 33% | KEV |
| masslikely >1M users across tens of thousands of exposed instances (Roundcube is bundled as webmail in cPanel/Plesk and by many ISPs) | |
| CVE-2023-5631 | Stored XSS in Roundcube Webmail exploited in the wild (CVE-2023-5631) CVE-2023-5631 is a stored cross-site scripting (XSS) flaw in Roundcube Webmail caused by insufficient sanitization of SVG content embedded in HTML email by program/lib/Roundcube/rcube_washtml.php. A remote attacker triggers it by sending a crafted HTML email containing a malicious SVG document; when the recipient views the message, arbitrary JavaScript is loaded in their browser session. This lets the attacker act as the victim within the webmail session — for example reading mail or capturing session data — and it has been used in targeted espionage rather than commodity attacks. Anyone running Roundcube before 1.4.15, 1.5.x before 1.5.5, or 1.6.x before 1.6.4 is affected, including Roundcube packages shipped by Debian and Fedora. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-10-26, the Winter Vivern espionage group is reported to have exploited it as a zero-day against government entities, and EPSS puts the 30-day exploitation probability at ~76% (99th percentile). Do: Upgrade to Roundcube 1.6.4, or 1.5.5 on the 1.5.x branch and 1.4.15 on the 1.4.x branch; apply the corresponding patched roundcube packages for Debian or Fedora. Per the CISA KEV required action, apply vendor mitigations or discontinue use if patching is unavailable. Hunt for compromise by reviewing webmail logs and stored messages for crafted SVG/HTML emails sent around the exploitation window, and review sessions for signs of hijacking. | 5.4 | 76% | KEV PoC |
| largetens of thousands of internet-exposed Roundcube servers; plausibly 100k+ end users, unknown precisely |
Full article501 words · extracted from therecord.media · click to collapse
A well-known espionage group typically seen supporting Russia and Belarus was caught exploiting a zero-day vulnerability affecting a popular webmail service used by governments across Europe. Researchers at security firm ESET said they have been tracking a new campaign by Winter Vivern —- an advanced persistent threat (APT) group previously implicated in cyberattacks on the governments of Poland, Ukraine and India. The latest campaign involved the exploitation of a previously unknown bug affecting Roundcube Webmail software, which is free and open-source. ESET said it informed Roundcube of the vulnerability, tracked as CVE-2023-5631, after discovering it on October 12. A patch was released on October 14. ESET researcher Matthieu Faou explained that the campaign targeted Roundcube servers belonging to governmental entities and a think tank, all based in Europe. The vulnerability was notable because it required no manual interaction other than simply viewing a malicious email message in a web browser. Hackers could use the issue to exfiltrate email messages. “Winter Vivern is a threat to governments in Europe because of its persistence, its very consistent running of phishing campaigns, and because a significant number of internet-facing applications are not regularly updated despite being known to contain vulnerabilities,” Faou said. Faou noted that the attack was novel because the related emails did not seem malicious. But when examined, the messages revealed payloads that gave the hackers access to the email account information. Faou and ESET have been tracking Winter Vivern since the group emerged in 2020. The group specifically targets government organizations in Europe and Central Asia, using an array of malicious documents, phishing websites and other tools in their attacks. ESET tied the group to another Belarus-linked espionage group, known as MoustachedBouncer, in August. The company noted that Winter Vivern has long targeted Zimbra and Roundcube email servers, specifically going after government entities using the services since 2022. ESET noted that the group previously targeted CVE-2020-35730, which affects Roundcube as well. SentinelOne reported attacks by Winter Vivern in March that involved phishing sites, malware and more. Other Russia-based hacking groups have targeted Roundcube in the past. Hackers with the infamous Russian military cyber group APT28 — also known as Fancy Bear and BlueDelta — were accused in June of targeting the Ukrainian government and a company involved in military aviation through three different vulnerabilities in Roundcube’s Webmail service. ESET said it saw APT28 using CVE-2020-35730 in attacks, at times attacking the same organizations as Winter Vivern with the vulnerability. “Winter Vivern has stepped up its operations by using a zero-day vulnerability in Roundcube,” ESET said. “Previously, it was using known vulnerabilities in Roundcube and Zimbra, for which proofs of concept are available online.”
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/winter-vivern-hackers-roundcube-webmail-zero-day