Inside the Arsenal: Exposed Server Reveals APT28’s ‘Roundish’ Toolkit and Advanced Cyber Espionage Tactics
ID: be668d1c-ee25-5868-b494-b9766241ce01
STIX ID: report--be668d1c-ee25-5868-b494-b9766241ce01
Feed Name: securityonline.info
Threat Score
### Executive Summary Hunt Intelligence uncovered an exposed open directory containing the "Roundish" espionage toolkit linked to APT28, revealing development and operational artifacts including Flask-based C2, a 5.2 MB Go implant ('httd') for persistence, CSS side-channel and browser credential-stealing techniques, and evidence of active reconnaissance and exfiltration targeting the Ukrainian State Migration Service.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
