logo
Russian group Sednit using webmail flaws to target Ukraine allies

Russian group Sednit using webmail flaws to target Ukraine allies

Techday NZ16-05-2025

ESET researchers have identified an espionage campaign dubbed Operation RoundPress, which targets webmail servers using cross-site scripting (XSS) vulnerabilities and is most likely orchestrated by the Russia-aligned Sednit group.
Operation RoundPress leverages spearphishing emails that exploit vulnerabilities in popular webmail platforms, including Roundcube, Horde, MDaemon, and Zimbra, to deliver malicious JavaScript payloads directly into victims' webmail pages.
The primary focus of the campaign appears to be governmental entities and defence companies linked to the ongoing conflict in Ukraine. ESET has reported that many of the affected defence companies in Bulgaria and Romania are actively engaged in producing Soviet-era weapons for shipment to Ukraine.
ESET's research also notes that other government-related targets span across Africa, the European Union, and South America, highlighting the international reach of the campaign.
Matthieu Faou, ESET Researcher, explained the technical nature of the attacks, stating: "Last year, we observed different XSS vulnerabilities being used to target additional webmail software: Horde, MDaemon, and Zimbra. Sednit also started to use a more recent vulnerability in Roundcube, CVE-2023-43770. The MDaemon vulnerability — CVE-2024-11182, now patched — was a zero day, most likely discovered by Sednit, while the ones for Horde, Roundcube, and Zimbra were already known and patched."
According to ESET, Sednit sends emails containing XSS exploits, which, once opened by the target in a vulnerable webmail portal, execute malicious JavaScript in the context of the user's session. This technique gives attackers access to only the data available through the compromised account, such as credentials, contacts, and email messages.
The success of this form of attack relies on convincing recipients to open the malicious email in their webmail client. The spearphishing emails are crafted to evade spam filters and employ credible subject lines mimicking news headlines. ESET's findings identified fake headlines such as: "SBU arrested a banker who worked for enemy military intelligence in Kharkiv" and "Putin seeks Trump's acceptance of Russian conditions in bilateral relations". The emails often cited well-known news outlets like Ukraine's Kyiv Post and Bulgaria's News.bg to increase believability.
ESET reports that various JavaScript payloads, including SpyPress.HORDE, SpyPress.MDAEMON, SpyPress.ROUNDCUBE, and SpyPress.ZIMBRA, are deployed depending on the targeted platform. These tools are able to steal webmail credentials, exfiltrate contact lists and address books, and access email correspondence. Of particular note, the SpyPress.MDAEMON variant can bypass two-factor authentication protections by extracting the authentication secret and creating an app-specific password, permitting attackers direct mailbox access via a mail application.
Faou expanded further on the attackers' motivations and the vulnerabilities exploited, adding: "Over the past two years, webmail servers such as Roundcube and Zimbra have been a major target for several espionage groups, including Sednit, GreenCube, and Winter Vivern. Because many organizations don't keep their webmail servers up to date, and because the vulnerabilities can be triggered remotely by sending an email message, it is very convenient for attackers to target such servers for email theft."
The Sednit group, also known as APT28, Fancy Bear, Forest Blizzard, or Sofacy, has a documented history of cyberespionage dating back to at least 2004. The group has been previously named by the U.S. Department of Justice as responsible for the Democratic National Committee breach preceding the 2016 U.S. elections and has links to the GRU, Russia's military intelligence agency. Other high-profile attacks attributed to Sednit include the compromise of TV5Monde, the World Anti-Doping Agency email leak, among other incidents.

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Four killed, 80 wounded in intense Russian air attacks on Ukraine
Four killed, 80 wounded in intense Russian air attacks on Ukraine

RNZ News

timean hour ago

  • RNZ News

Four killed, 80 wounded in intense Russian air attacks on Ukraine

By Thomas Peter, Anna Voitenko and Anastasiia Malenko, Reuters People stand outside an apartment block in the Solomianskyi district damaged by an overnight Russian attack in Kyiv, Ukraine, on June 6, 2025. Photo: AFP / NurPhoto/ Kirill Chubotin Russia launched an intense missile and drone barrage at the Ukrainian capital Kyiv in the early hours of Friday, killing four people, Ukrainian President Volodymyr Zelensky said, as powerful explosions reverberated across the country. The attacks followed a warning from Russian President Vladimir Putin, conveyed via US President Donald Trump , that the Kremlin would hit back after Ukrainian drones destroyed several strategic bomber aircraft in attacks deep inside Russia. Zelensky said three emergency responders were killed in the missile and drone salvo against the capital. Another person died in an attack on the northwestern city of Lutsk. "Those killed in Kyiv were rescue workers who arrived at the scene of an initial strike and, unfortunately, were killed in a repeat Russian strike," Zelensky said in his nightly video address. Foreign Minister Andrii Sybiha, writing on X, said Russia had "'responded' to its destroyed aircraft... by attacking civilians in Ukraine.... Multi-storey buildings hit. Energy infrastructure damaged." Russia's Defence Ministry said its forces had carried out the strike on military and military-related targets in response to what it called Ukrainian "terrorist acts" against Russia. Zelensky said 80 people nationwide had been injured in the attacks, which also struck several other towns and cities. He said residents could still be trapped under rubble. In Lutsk, the national emergency service said 30 people were injured in addition to the one death. Prosecutors said the attack damaged private homes, educational institutions and a government building. Russian forces also struck industrial facilities and infrastructure in the western city of Ternopil, leaving parts of it without power, mayor Serhii Nadal said. The regional administration said the attack had injured 10 people and asked residents to temporarily stay inside due to a high concentration of toxic substances in the air after a fire. The air force said Russia had used 407 drones, one of the largest numbers recorded in a single attack. Forty-five cruise and ballistic missiles were also fired, it said. Kyiv's metro transport system was disrupted by a Russian strike that hit and damaged tracks between stations, the military administration said. The state rail company said it was also diverting some trains due to rail damage outside the city. Reuters witnesses reported a series of booming explosions powerful enough to rattle windows far from the impact sites. Some Kyiv residents sought shelter in metro stations, or in underground car parks. In the capital's Solomianskyi district, a Russian drone slammed into the side of an apartment building, leaving a gaping hole and burn marks, a Reuters photographer at the scene said. Falling concrete blocks from the building crushed cars parked below. Two police investigators were examining what appeared to be the drone's engine. Earlier in the night, Reuters reporters heard the sound of Russian kamikaze drones buzzing in the sky, accompanied by the sounds of outgoing fire from Ukrainian anti-aircraft batteries. Zelensky called for concerted pressure on Russia. "If someone is not applying pressure and is giving the war more time to take lives that is complicity and accountability. We must act decisively," he wrote on X. The Ukrainian military said it had launched a pre-emptive strike overnight on the Engels and Dyagilevo airfields in the Russian regions of Saratov and Ryazan, in addition to striking at least three fuel reservoirs. In one of the most audacious attacks of the three-year-old war between Ukraine and Russia, Ukrainian spies last weekend destroyed some of Russia's strategic bomber aircraft on the ground using quadrocopter drones hidden in wooden sheds. After a phone conversation with Putin on Wednesday, Trump said the Kremlin was planning an unspecified response to the Ukrainian attack on the Russian air bases.

No immediate peace for Ukraine; UK avoids 50% aluminium tariff
No immediate peace for Ukraine; UK avoids 50% aluminium tariff

National Business Review

time2 days ago

  • National Business Review

No immediate peace for Ukraine; UK avoids 50% aluminium tariff

Ata mārie and welcome to your Thursday overview of the business and political stories making headlines. First up, Russian President Vladimir Putin has spoken to US President Donald Trump by phone and there appeared to be no immediate peace solution for Ukraine. Putin said he was obligated to respond to Ukraine's weekend drone attack, setting up a potential escalation in the conflict, CNN reported. Trump said the 75-minute conversation would not end the war in Ukraine immediately. 'We discussed the attack on Russia's docked airplanes, by Ukraine, and also various other attacks that have been taking place by both sides,' Trump said. 'It was a good conversation, but not a conversation that will lead to immediate peace. President Putin did say, and very strongly, that he will have to respond to the recent attack on the airfields.' CNBC reported that Trump and Putin also discussed Iran, and that time was running out for Iran's decision about nuclear weapons. Earlier, the BBC said a report by the UN nuclear watchdog concluded Iran had increased production of enriched uranium, a key component in making nuclear weapons. Elsewhere, the White House signalled that the UK could be spared from the fresh 50% steel and aluminium tariffs this week, the Guardian reported. Trump said he had decided to 'provide different treatment' to the UK, after a trade deal was agreed but yet to be signed between the two countries. UK Prime Minister Keir Starmer said that deal would be implemented 'within a very short time'. US President Donald Trump. Meanwhile, a provision in the more than 1000-page 'One Big Beautiful Bill Act' concerned foreign investors, the BBC reported. Section 899, known as the "revenge tax" by critics, could let the US introduce higher taxes on investors from countries with tax policies that the US did not like. The BBC said that could include digital-services taxes on technology companies. The bill had passed narrowly in the House of Representatives but still faced Senate scrutiny. If passed, Section 899 could raise tax burdens for multinationals, investors, and wealthy families, which could put US investment on ice, the BBC noted. In Gaza, around 100 Palestinians had been killed and 440 injured after a series of attacks by Israel over the past 24 hours, Al Jazeera reported. Israel's military warned starving people to avoid aid distribution sites run by the controversial Gaza Humanitarian Foundation. That was because of a planned closure for renovation and reorganisation, along with 'efficiency improvement' work. The BBC also said that roads leading to the distribution centres were considered "combat zones" during the closures. Destroyed homes in Gaza. In business news, Nissan's new chief executive Ivan Espinosa was brushing off a tough global economy, competition from China, and trade tariffs, with the need to stay flexible, CNBC reported. 'Keep the optimism up, because the environment is very tough, and you don't want to get overwhelmed. You need to keep moving. 'It's a very turbulent environment we live in. In the past, some CEOs were very stubborn, very resistant to change. You need to stay open and stay flexible.' He noted more collaboration in the automotive industry in the face of growing geopolitical tension and supply chain challenges. 'Sometimes, it's just not possible to go it alone.' Finally, a story from the quirky files, after a large elephant entered a shop in Thailand in search of food, CNN reported. CCTV footage revealed the hungry animal entered the convenience store and helped itself to snacks this week. 'The elephant just walked right up. I came out and tried to shoo it away. I told it not to come closer,' shop owner Khamploi Kakaew told CNN. The shop is located northeast of the capital Bangkok, near the Khao Yai National Park.

Trump says Putin 'playing with fire' in new jab at Russian leader
Trump says Putin 'playing with fire' in new jab at Russian leader

RNZ News

time27-05-2025

  • RNZ News

Trump says Putin 'playing with fire' in new jab at Russian leader

By Kylie Atwood, Kristen Holmes, Kevin Liptak and Matthew Chance , CNN Donald Trump says he doesn't know what's wrong with Valadimir Putin as more people die in Russia's war with Ukraine. Photo: AFP / Brendan Smialowski When President Donald Trump spoke last week by telephone with Vladimir Putin, the Russian leader committed to drafting and sending what he described as a "memorandum of peace" in the coming days laying out Russian requirements for a ceasefire with Ukraine, according to a US official and White House official familiar with the matter. But more than a week after that phone call, the US has yet to receive the document from Russia, the sources said. Now, Trump is considering moving ahead with new sanctions on Moscow in the coming days as he vents his fury at the state of the conflict, according to people familiar with the matter. Options were drawn up in the past several weeks to apply new measures punishing Moscow, but so far Trump has not approved them. The president said on Sunday (US time) he would "absolutely" consider new sanctions in the aftermath of a sustained missile and drone bombardment that left many dead. "He's killing a lot of people," Trump said of Putin on Sunday. "I don't know what's wrong with him. What the hell happened to him?" And in a Truth Social post on Tuesday, the president wrote: "What Vladimir Putin doesn't realize is that if it weren't for me, lots of really bad things would have already happened to Russia, and I mean REALLY BAD. He's playing with fire!" Trump could still decide not to apply the new sanctions, the people said, in keeping with past examples of him backing away from threats to target Russia over its actions in Ukraine. Trump has said privately he is concerned new sanctions could push Russia away from peace talks. During their call last Monday , Trump told Putin that Russia and Ukraine should be communicating directly to negotiate a peace accord, and that Europe and the United States would help when needed, a White House official said. After that call, Trump said on social media that the conditions for a ceasefire "will be negotiated between the two parties, as it can only be". The call came just days after the first direct talks between Ukraine and Russia in Turkey. When those talks ended, the expectation was that a follow-up Russian memo would be shared with Ukraine. But the plan for Russia to send its memorandum not just to Ukraine but also to the US indicates that Trump concluded the call without completely washing his hands of potential future involvement. US Secretary of State Marco Rubio Photo: Pool / AFP / Jacquelyn Martin Secretary of State Marco Rubio also spoke with Russian Foreign Minister Sergey Lavrov the day before the Trump-Putin call and said they discussed the topic. Lavrov told Rubio at the time that Russian officials would be "preparing a document outlining their requirements for a ceasefire that would then lead to broader negotiations", Rubio told CBS' Face the Nation last week. He added that if that came forward, along with Ukrainian proposals, "we can work off of that." "Hopefully that will be forthcoming soon," Rubio added. On Tuesday, Russian Foreign Ministry spokesperson Maria Zakharova said Moscow was working on the document. "Russia continues the development of the draft memorandum regarding the future peace treaty with the definition of a number of positions, such as: principles of settlement, timeframes of possible conclusion of peace agreement (and) potential ceasefire for a certain time in case of reaching corresponding agreements," Zakharova said. "As soon as the memorandum is prepared, it will be handed over to Kyiv," her statement continued. "We expect that the Ukrainian side is conducting the same work and will send us its developments simultaneously with the receipt of the Russian document." While the US waits on Russia - with mounting frustration - Ukrainian President Volodymyr Zelensky on Monday accused Putin of "simply playing games with diplomacy and diplomats". Meanwhile, Democratic and Republican lawmakers have begun lobbying Trump to significantly ratchet up US sanctions after the weekend attacks. "All of us, by our public statements as well as private contacts, are pressing very, very hard," Democratic Senator Richard Blumenthal told CNN on Monday. Blumenthal is a key figure behind a cross-party Senate bill, also sponsored by Trump ally Senator Lindsey Graham, which aims to impose "crippling" new measures on Moscow. It would include "secondary sanctions," like massive 500 percent tariffs on countries buying Russian energy. More than 80 senators have signed on to the bipartisan bill so far. According to Blumenthal, the cross-party bill - which could impact US adversaries like China as well as friendly Asian and European nations - was drawn up in "very extensive" consultation with US allies who may be affected by new sanctions on Russian energy imports. Germany, France and Britain are now "all for it, with 100 percent support", he told CNN. After speaking with Putin last week, Trump told European leaders on a telephone call that he would not join them, for now, in applying new measures on Moscow, even though he had previously signalled a willingness to take a tougher approach to Putin, a European official said. Trump "believes, that right now if you start threatening sanctions, the Russians will stop talking, and there is value in us being able to talk to them and to drive them to get to the table", Secretary of State Marco Rubio told lawmakers on the Senate Foreign Relations Committee last week, a day after Trump and Putin spoke over the phone. "Like we will see, look they have to do this, no one is claiming that this is a guarantee." After Trump's most recent comments, French President Emmanuel Macron voiced hope the US leader would change course. "President Trump realizes that when President Putin said on the phone he was ready for peace, or told his envoys he was ready for peace, he lied," Macron said Monday. "We have seen once again in recent hours Donald Trump express his anger. A form of impatience. I simply hope now that this translates into action." Trump has previously raised the notion of new sanctions on Russia's banking sector and secondary sanctions on purchasers of Russian energy products. Both options have been drawn up, but it wasn't clear what specific steps Trump was considering in the wake of Russia's weekend bombardment in Ukraine. -AFP

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into the world of global news and events? Download our app today from your preferred app store and start exploring.
app-storeplay-store