×
ItalianoEnglish
Set as default language

Grandangolo Communications

  • Home
  • Company
  • Services
    • Public Relation
    • Digital PR
    • Marketing
    • Lead Generation
    • Events
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages
  • Home
  • Customer Press Room
  • Eset
  • ESET unmasks the RoundPress operation of the Sednit group aligned with Russia

Customer Press Room

ESET unmasks the RoundPress operation of the Sednit group aligned with Russia

by Grandangolo Communications / Thursday, 15 May 2025 / Published in Eset

The email espionage campaign exploits XSS vulnerabilities in webmails such as Roundcube, Horde, MDaemon and Zimbra. Government targets and defense companies targeted, with theft of credentials, contacts and messages, and the possibility of bypassing two-factor authentication

Researchers of ESET, a global European leader in the cybersecurity market, have uncovered a cyber espionage operation attributed with reasonable certainty to the Russia-aligned Sednit Group, called RoundPress. The campaign targets webmail servers by exploiting XSS vulnerabilities with the ultimate goal of stealing confidential data from specific email inboxes. Most of the targets are linked to the ongoing conflict in Ukraine: they are mainly Ukrainian administrations or defense companies in Bulgaria and Romania. Some of these companies produce Soviet-era weapons destined for Ukraine. Other targets include African, EU and South American governments.

"Last year – explains Matthieu Faou, ESET researcher who discovered and analyzed Operation RoundPress – we observed the use of several every probability discovered by the group itself, while those of Horde, Roundcube and Zimbra were already known and patched”.

Sednit delivers these XSS exploits via email; the victim opening the message in a vulnerable webmail leads to the execution of malicious JavaScript code within the page. As a result, only data accessible from the victim's account can be read and exfiltrated.

For the exploit to work, the victim must open the message in the vulnerable web interface. This implies that the email must pass anti-spam filters and that the subject of the message is credible enough to push the user to read it. To achieve this goal, the attackers exploited the visual identity of well-known newspapers such as Kyiv Post or the Bulgarian portal News.bg. Among the headlines used to make spearphishing messages credible are, for example: “SBU arrests banker who worked for enemy military intelligence in Kharkiv” and “Putin seeks Trump's acceptance of Russian conditions in bilateral relations”.

The JavaScript payloads used include SpyPress.HORDE, SpyPress.MDAEMON, SpyPress.ROUNDCUBE, and SpyPress.ZIMBRA. These are capable of stealing credentials, stealing address books, contacts and activity history, as well as reading email messages. SpyPress.MDAEMON, in particular, allows you to bypass two-factor protection by obtaining the authentication key and generating an access credential, which allows attackers to consult the mailbox via an email client.

"Over the past two years – adds Faou – webmail servers such as Roundcube and Zimbra have been prime targets for several espionage groups, including Sednit, GreenCube and Winter Vivern. Since many organizations do not update their webmails and vulnerabilities can be activated simply by sending an email, these servers represent a very convenient target for the exfiltration of email communications."

The Sednit group — also known as APT28, Fancy Bear, Forest Blizzard or Sofacy — has been active since at least 2004. The US Department of Justice named it as responsible for the attack on the Democratic National Committee (DNC) servers before the 2016 US presidential election and linked it to the military intelligence agency of the Russian Federation (GRU). Other attacks are also attributed to the group, including the one on the French television network TV5Monde and the theft of emails from the World Anti-Doping Agency (WADA).

For a detailed and technical analysis of the tools used by Sednit in Operation RoundPress, the full post is available on the ESET Research blog, “Operation RoundPress", are WeLiveSecurity.com. To stay updated on the latest news you can follow ESET Research on X (formerly known as Twitter), BlueSky e Mastodon.

Tagged under: Eset

About Grandangolo Communications

What you can read next

ESET Releases Q2 Threat Report - Cybercriminals Profit from Users Adapting to a 'Covidian' World
ESET Research reveals the secrets of the Asylum Ambuscade group
ESET presents the projects for the ESET Campus: an innovation and technology hub in the heart of Europe

Customer Press Room

  • Acronis Introduces MDR by Acronis TRU to Offer MSPs 24/7 Threat Detection and Response

    The service allows MSPs to offer customers...
  • SentinelOne expands strategic partnership with Google Cloud to deliver AI-powered autonomous security on a global scale

    The partnership will lead to the development of new...
  • Vertiv Announces Expansion of Manufacturing Capacity in Infrastructure Solutions, Energy and Rack Systems to Meet Growing Demand

    New and expanded production facilities in America...
  • Eon and SentinelOne partner to improve cloud data security and AI resilience

    The combination of features will broaden the ...
  • Vertiv expands thermal portfolio with new wall cooling system for edge and small data rooms in EMEA

    Designed to operate 24/7 in busy environments...

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018

Categories

  • A10
  • abstract
  • Abstract
  • Acronis
  • Ally Consulting
  • Arrow
  • Arrow Electronics
  • Axiante
  • Babel
  • Computer Center
  • Cohesity
  • Italy Cloud Consortium
  • Consys
  • D-Link
  • Eset
  • G.B. Service
  • Habble
  • HiSolution
  • HYCU
  • Icos
  • Information Tecnology
  • Innovaway
  • Ivanti
  • Link11
  • MobileIron
  • Netalia
  • Nethive
  • Nexthink
  • Nuvis
  • Praim
  • QAD
  • Qualys
  • Red Hot Cyber
  • Riverbed
  • Saviynt
  • Sensormatic
  • SentinelOne
  • Talent Software
  • Vectra
  • Vectra AI
  • Vertiv

Office printing, digital PR, marketing, lead generation: all projects are born from our passion and expertise, with an inevitable touch of creativity and innovation.

COMPANY

Grandangolo Communications Srl
Via Sardegna 19
20146 Milano
Telephone +39 335 8283393
info@grandangolo.it

I SERVIZI

  • Home
  • Company
  • Services
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages

CONTACTS

  • Contacts
  • Cookie policy
  • Privacy policy

© 2019 GRANDANGOLO COMMUNICATIONS SRL | P.IVA IT 06394850967 | All rights reserveD.

Powered by Webpowerplus

TOP