UNC1151 exploiting Roundcube to steal user credentials in a spearphishing campaign
ID: 2f5d779f-74ed-572c-9b95-ccc255c61993
STIX ID: report--2f5d779f-74ed-572c-9b95-ccc255c61993
Feed Name: CERT Polska
CERT Polska reports a spear-phishing campaign targeting Polish entities that exploited Roundcube XSS (CVE-2024-42009) to install a Service Worker which intercepted and exfiltrated webmail credentials to a.mpk-krakow.pl; the activity is attributed with high confidence to UNC1151, includes observable IoCs (sender emails, SMTP source, JS attachment hash, malicious domain), and advises updating Roundcube, investigating logs, resetting compromised credentials, and unregistering Service Workers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
