Government webmail hacked via XSS bugs in global spy campaign
ID: 4a501170-cb2b-5c4d-afc8-736fef4d6be3
STIX ID: report--4a501170-cb2b-5c4d-afc8-736fef4d6be3
Feed Name: Bleeping Computer
Operation RoundPress is a 2023–2024 cyber‑espionage campaign attributed to APT28 that leverages stored and reflected XSS (including a reported zero‑day) in popular webmail servers—Roundcube, MDaemon, Horde and Zimbra—to execute malicious JavaScript when a specially crafted email is opened, harvest credentials, email content, 2FA and settings, and exfiltrate the data to hardcoded C2 endpoints; victims included government, military, defense contractors and critical infrastructure across multiple countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
