logo

APT28 Exploits Roundcube Vulnerabilities in Targeted Cyber Espionage Campaign

ID: fc4e1330-158b-556a-bca4-9de3935fbf01

STIX ID: report--fc4e1330-158b-556a-bca4-9de3935fbf01

Feed Name: ThreatCluster

Threat Score
88/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

...
...

APT28’s Operation Roundish uses a comprehensive Roundcube exploitation toolkit—containing XSS payloads, a command-and-control server, credential-harvesting tools, persistent mail-forwarding, and 2FA secret extraction—to target Ukrainian government entities and other organizations across eleven countries; exploitation of CVE-2023-43770 has been confirmed, indicating active, sophisticated abuse of webmail vulnerabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.