By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers
Tech News

Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers

By Viral Trending Content 6 Min Read
Share
SHARE

A Russia-linked threat actor has been attributed to a cyber espionage operation targeting webmail servers such as Roundcube, Horde, MDaemon, and Zimbra via cross-site scripting (XSS) vulnerabilities, including a then-zero-day in MDaemon, according to new findings from ESET.

The activity, which commenced in 2023, has been codenamed Operation RoundPress by the Slovak cybersecurity company. It has been attributed with medium confidence to the Russian state-sponsored hacking group tracked as APT28, which is also referred to as BlueDelta, Fancy Bear, Fighting Ursa, Forest Blizzard, FROZENLAKE, Iron Twilight, ITG05, Pawn Storm, Sednit, Sofacy, and TA422.

“The ultimate goal of this operation is to steal confidential data from specific email accounts,” ESET researcher Matthieu Faou said in a report shared with The Hacker News. “Most victims are governmental entities and defense companies in Eastern Europe, although we have observed governments in Africa, Europe, and South America being targeted as well.”

This is not the first time APT28 has been tied to attacks exploiting flaws in webmail software. In June 2023, Recorded Future detailed the threat actor’s abuse of multiple flaws in Roundcube (CVE-2020-12641, CVE-2020-35730, and CVE-2021-44026) to conduct reconnaissance and data gathering.

Cybersecurity

Since then, other threat actors like Winter Vivern and UNC3707 (aka GreenCube) have also targeted email solutions, including Roundcube, in various campaigns over the years. Operation RoundPress’ ties to APT28 stem from overlaps in the email address used to send the spear-phishing emails and similarities in the way certain servers were configured.

A majority of the targets of the campaign in 2024 have been found to be Ukrainian governmental entities or defense companies in Bulgaria and Romania, some of which are producing Soviet-era weapons to be sent to Ukraine. Other targets include government, military, and academic organizations in Greece, Cameroon, Ecuador, Serbia, and Cyprus.

The attacks entail the exploitation of XSS vulnerabilities in Horde, MDaemon, and Zimbra to execute arbitrary JavaScript code in the context of the webmail window. It’s worth noting that CVE-2023-43770, an XSS bug in Roundcube, was added by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to its Known Exploited Vulnerabilities (KEV) catalog in February 2024.

While the attacks targeting Horde (an unspecified old flaw fixed in Horde Webmail 1.0 released in 2007), Roundcube (CVE-2023-43770), and Zimbra (CVE-2024-27443) leveraged security defects already known and patched, the MDaemon XSS vulnerability is assessed to have been used by the threat actor as a zero-day. Assigned the CVE identifier CVE-2024-11182 (CVSS score: 5.3), it was patched in version 24.5.1 last November.

“Sednit sends these XSS exploits by email,” Faou said. “The exploits lead to the execution of malicious JavaScript code in the context of the webmail client web page running in a browser window. Therefore, only data accessible from the victim’s account can be read and exfiltrated.”

However, for the exploit to be successful, the target must be convinced to open the email message in the vulnerable webmail portal, assuming it’s able to bypass the software’s spam filters and land on the user’s inbox. The contents of the email themselves are innocuous, as the malicious code that triggers the XSS flaw resides within the HTML code of the email message’s body and, therefore, is not visible to the user.

Successful exploitation leads to the execution of an obfuscated JavaScript payload named SpyPress that comes with the ability to steal webmail credentials and harvest email messages and contact information from the victim’s mailbox. The malware, despite lacking a persistence mechanism, gets reloaded every time the booby-trapped email message is opened.

Cybersecurity

“In addition, we detected a few SpyPress.ROUNDCUBE payloads that have the ability to create Sieve rules,” ESET said. “SpyPress.ROUNDCUBE creates a rule that will send a copy of every incoming email to an attacker-controlled email address. Sieve rules are a feature of Roundcube and therefore the rule will be executed even if the malicious script is no longer running.”

The gathered information is subsequently exfiltrated via an HTTP POST request to a hard-coded command-and-control (C2) server. Select variants of the malware have also been found to capture login history, two-factor authentication (2FA) codes, and even create an application password for MDAEMON to retain access to the mailbox even if the password or the 2FA code gets changed.

“Over the past two years, webmail servers such as Roundcube and Zimbra have been a major target for several espionage groups such as Sednit, GreenCube, and Winter Vivern,” Faou said. “Because many organizations don’t keep their webmail servers up to date and because the vulnerabilities can be triggered remotely by sending an email message, it is very convenient for attackers to target such servers for email theft.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Using Self-Checking Loops GPT-5.2 Hits 75% on ARC-AGI

Surplus Wind End Energy Poverty Alan Wylie of EnergyCloud

What Is a Preamp, and Do I Really Need One?

Your guide to complete visibility

How do you dispose of old batteries? Derry Cronin, Business Development Director of EHS International

TAGGED: APT28, cyber espionage, Cyber Security, Cybersecurity, email security, Internet, Malware, Roundcube, Vulnerability, Webmail, Zimbra
Share This Article
Facebook Twitter Copy Link
Previous Article Today in History: May 19, West Virginia’s Matewan Massacre
Next Article Tether surpasses Germany's $111B of US Treasury holdings
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Israel says it will halt operations of some aid organisations in Gaza starting in 2026
World News
Pipe Bomb Suspect’s Attorneys Say He Has OCD, Autism, in Their Request Not to Detain
Politics
Varun Beverages stock gets a '7 Up' on Twizza acquisition
Business
Using Self-Checking Loops GPT-5.2 Hits 75% on ARC-AGI
Tech News
2026 Fed cuts will be ‘key catalyst’ for retail's return to crypto
Crypto
One Year Later: Remembering Dragon Age: The Veilguard’s Mess
Gaming News
Man Utd 1-1 Wolves: Gary Neville slams "bizarre" Ruben Amorim decision
Sports

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Israel says it will halt operations of some aid organisations in Gaza starting in 2026

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Israel says it will halt operations of some aid organisations in Gaza starting in 2026
December 31, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?