APT28 Exploits Roundcube Vulnerabilities in Targeted Cyber Espionage Campaign
ID: fc4e1330-158b-556a-bca4-9de3935fbf01
STIX ID: report--fc4e1330-158b-556a-bca4-9de3935fbf01
Feed Name: ThreatCluster
Threat Score
APT28’s Operation Roundish uses a comprehensive Roundcube exploitation toolkit—containing XSS payloads, a command-and-control server, credential-harvesting tools, persistent mail-forwarding, and 2FA secret extraction—to target Ukrainian government entities and other organizations across eleven countries; exploitation of CVE-2023-43770 has been confirmed, indicating active, sophisticated abuse of webmail vulnerabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
