logo

Inside the Arsenal: Exposed Server Reveals APT28’s ‘Roundish’ Toolkit and Advanced Cyber Espionage Tactics

ID: be668d1c-ee25-5868-b494-b9766241ce01

STIX ID: report--be668d1c-ee25-5868-b494-b9766241ce01

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-03-16

Date Updated: 2026-04-23

Author: Ddos

...
...

### Executive Summary Hunt Intelligence uncovered an exposed open directory containing the "Roundish" espionage toolkit linked to APT28, revealing development and operational artifacts including Flask-based C2, a 5.2 MB Go implant ('httd') for persistence, CSS side-channel and browser credential-stealing techniques, and evidence of active reconnaissance and exfiltration targeting the Ukrainian State Migration Service.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.