logo

Russian Hackers Hit Mail Servers in Europe for Political and Military Intel

ID: 56f64e5c-c96d-51c1-be2b-fab4ee8acff9

STIX ID: report--56f64e5c-c96d-51c1-be2b-fab4ee8acff9

Feed Name: HackRead

Threat Score
90/100

Date Published: 2024-02-19

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Recorded Future’s Insikt Group attributes an espionage campaign to TAG-70 (aka Winter Vivern) that exploited a Roundcube webmail XSS/zero-day (CVE-2023-563) and used spearphishing and JavaScript payloads to compromise mail servers across ~80 organizations in Europe — notably Ukraine, Georgia, and Poland — to collect political and military intelligence, including targeting embassies and critical infrastructure between October and December 2023.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.