ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

Russian Espionage Operation Targets Organizations Tied to Ukraine War

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-43770
Persistent Cross-Site Scripting in Roundcube Webmail (Exploited in the Wild)

Roundcube Webmail versions before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 contain a persistent cross-site scripting (XSS) flaw (CWE-79) caused by how program/lib/Roundcube/rcube_string_replacer.php converts plain text into clickable links. An attacker sends a text/plain email containing crafted links; when the recipient views the message, the crafted link text is turned into HTML that runs attacker-controlled script, which persists and executes in the victim's webmail session. Successful exploitation lets the attacker execute JavaScript with the victim's session, enabling mailbox access, theft of session credentials, and actions performed as the user (CVSS 6.1, scope-changed with limited confidentiality and integrity impact). Anyone running an affected Roundcube instance is exposed, including the roundcube package shipped with Debian Linux. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-02-12, and EPSS assigns a 58.5% probability of exploitation within 30 days (99th percentile).

Do: Upgrade Roundcube to 1.4.14, 1.5.4, or 1.6.3 (or later, per branch), or install the updated roundcube package on Debian. Because the bug is in CISA's KEV catalog, U.S. federal agencies must apply the vendor fix by the catalog due date, and other defenders should prioritize patching internet-facing webmail servers. Review webmail access logs for suspicious message views or account activity, and consider forcing session re-authentication for accounts that opened crafted plain-text messages.

6.158% KEV
  • Roundcube Webmail before 1.4.14; 1.5.x before 1.5.4; 1.6.x before 1.6.3
  • Debian Linux (roundcube package)
massplausibly millions of users across tens of thousands of internet-exposed Roundcube instances (estimate)
CVE-2024-11182
Unauthenticated Cross-Site Scripting (XSS) in MDaemon Email Server Webmail

MDaemon Email Server versions before 24.5.1c contain a cross-site scripting flaw (CWE-79) in its handling of HTML email: JavaScript embedded in an img tag is not properly sanitized. A remote, unauthenticated attacker can trigger it simply by sending a crafted HTML email that a webmail user then opens, requiring no privileges but relying on user interaction. Successful exploitation loads attacker-supplied JavaScript in the context of the webmail user's browser window, which could enable session or credential theft and further intrusions from that user's session. Any organization running an affected MDaemon version with users of its webmail client is affected; MDaemon is a commercial on-premises Windows mail server used mainly by small and mid-sized organizations. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-05-19, and public reporting ties MDaemon exploitation to Russia-linked APT28 (Fancy Bear) campaigns that targeted the email of high-level Ukrainians and their military suppliers.

Do: Upgrade to MDaemon Email Server 24.5.1c or later, prioritizing installations whose webmail is exposed to the internet, since the flaw is actively exploited and KEV-listed. Review webmail access and message-viewing logs for suspicious activity, especially in organizations that may be targeted by APT28 (Ukrainian government, military, or defense-supply interests). Federal agencies must follow CISA KEV required actions (apply vendor mitigations per instructions and applicable BOD 22-01 guidance, or discontinue use if mitigations are unavailable) by the required due date.

5.318% KEV
  • MDaemon Technologies MDaemon Email Server all versions before 24.5.1c
moderatetens of thousands of on-premises deployments; plausibly on the order of 10,000–100,000 webmail users
Full article636 words · extracted from infosecurity-magazine.com · click to collapse

A new cyber espionage operation conducted by Russian hackers associated with the Kremlin is aiming to steal confidential data from organizations linked to the war in Ukraine.

Operation RoundPress, as ESET named it in a report on May 15, 2025, is a large-scale cyber espionage campaign conducted by Fancy Bear, which began at least as early as 2023.

Its primary targets are Ukrainian governmental entities or defense companies in Bulgaria and Romania, some of which are producing Soviet-era weapons to be sent to Ukraine. ESET has also observed governments in Africa, Europe and South America being targeted.

Its primary goal is to steal confidential data from specific email accounts.

Map of operation RoundPress victims in 2024. Source: ESET
Map of operation RoundPress victims in 2024. Source: ESET

Inside Operation RoundPress

In Operation RoundPress, the compromise vector is a spearphishing email leveraging an XSS vulnerability to inject malicious JavaScript code into the victim's webmail page.

In 2024, ESET observed different cross-site scripting (XSS) vulnerabilities being exploited to target additional webmail software, including Roundcube, Horde, MDaemon and Zimbra.

Upon investigating some of these exploits, the researchers found that Fancy Bear typically delivers these XSS exploits via email, allowing malicious JavaScript code to run within the webmail client's browser context, potentially exposing data accessible to the target's account.

“In order for the exploit to work, the target must be convinced to open the email message in the vulnerable webmail portal. This means that the email needs to bypass any spam filtering and the subject line needs to be convincing enough to entice the target into reading the email message — abusing well-known news media such as Ukrainian news outlet Kyiv Post or Bulgarian news portal News.bg,” wrote the ESET researchers.

Among the subject lines used in the spearphishing emails were: “SBU arrested a banker who worked for enemy military intelligence in Kharkiv” and “Putin seeks Trump’s acceptance of Russian conditions in bilateral relations”.

Then, the attackers unleash a series of JavaScript payloads, such as SpyPress.HORDE, SpyPress.MDAEMON, SpyPress.ROUNDCUBE and SpyPress.ZIMBRA. These can steal login credentials, exfiltrate email data and sometimes compromise two-factor authentication (2FA), enabling sustained access to victim mailboxes.

After focusing solely on Roundcube in 2023, Fancy Bear expanded to the other three webmail services in 2024.

“The MDaemon vulnerability – CVE-2024-11182, now patched – was a zero day, most likely discovered by the threat group, while the ones for Horde, Roundcube and Zimbra were older, already known flaws [that had been] patched,” said ESET researcher Matthieu Faou, who discovered and investigated Operation RoundPress.

More recently, the group also started to exploit a more recent vulnerability in Roundcube, CVE-2023-43770.

“Over the past two years, webmail servers such as Roundcube and Zimbra have been a major target for several espionage groups, including [Fancy Bear], GreenCube and Winter Vivern. Because many organizations don’t keep their webmail servers up to date, and because the vulnerabilities can be triggered remotely by sending an email message, it is very convenient for attackers to target such servers for email theft,” explains Faou.

In its report, ESET provided an analysis of the four JavaScript payloads.

Who is Behind Fancy Bear?

Fancy Bear is a Russian cyber espionage group known by many other names, including Sednit,  APT28, Pawn Storm, Forest Blizzard and Sofacy Group. The group has been active since 2004 and is believed to be affiliated with the Russian military intelligence agency (GRU).

In 2018, an indictment by the US Special Counsel identified Fancy Bear as GRU Unit 26165.

The US Department of Justice named the group as one of those responsible for the Democratic National Committee (DNC) hack just before the 2016 US elections. The group is also presumed to be behind the hacking of the global television network TV5Monde, the World Anti-Doping Agency (WADA) email leak, and many other incidents.

Read now: Russia-Backed APT28 Tried to Attack a Ukrainian Critical Power Facility

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/fancy-bear-russia-cyber-espionage/