logo

UNC1151 exploiting Roundcube to steal user credentials in a spearphishing campaign

ID: 2f5d779f-74ed-572c-9b95-ccc255c61993

STIX ID: report--2f5d779f-74ed-572c-9b95-ccc255c61993

Feed Name: CERT Polska

Threat Score
80/100

Date Published: 2025-06-05

Date Updated: 2026-04-19

Author: CERT Polska

...
...

CERT Polska reports a spear-phishing campaign targeting Polish entities that exploited Roundcube XSS (CVE-2024-42009) to install a Service Worker which intercepted and exfiltrated webmail credentials to a.mpk-krakow.pl; the activity is attributed with high confidence to UNC1151, includes observable IoCs (sender emails, SMTP source, JS attachment hash, malicious domain), and advises updating Roundcube, investigating logs, resetting compromised credentials, and unregistering Service Workers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.