ESET Research uncovers Operation RoundPress: Russia-aligned Sednit targets entities linked to the Ukraine war to steal confidential data
ESET researchers uncovered the Operation RoundPress espionage campaign, with Russia-aligned Sednit group most likely behind it.
In Operation RoundPress, the compromise vector is a spearphishing email leveraging an XSS vulnerability to inject malicious JavaScript code into the victim's webmail page. It targets Roundcube, Horde, MDaemon, and Zimbra webmail software.
Most victims are governmental entities and defense companies in Eastern Europe, although ESET has observed governments in Africa, Europe, and South America being targeted as well.
The payloads are able to steal webmail credentials, and exfiltrate contacts and email messages from the victim's mailbox.
Additionally, SpyPress.MDAEMON is able to set up a bypass for two-factor authentication.
MONTREAL and BRATISLAVA, Slovakia, May 20, 2025 (GLOBE NEWSWIRE) -- ESET researchers have uncovered a Russia-aligned espionage operation, which ESET named RoundPress, targeting webmail servers via XSS vulnerabilities. Behind it is most likely the Russia-aligned Sednit (also known as Fancy Bear or APT28) cyberespionage group, holding the ultimate goal of stealing confidential data from specific email accounts. Most of the targets are related to the current war in Ukraine; they are either Ukrainian governmental entities or defense companies in Bulgaria and Romania. Notably, some of these defense companies are producing Soviet-era weapons to be sent to Ukraine. Other targets include African, EU, and South American governments.
'Last year, we observed different XSS vulnerabilities being used to target additional webmail software: Horde, MDaemon, and Zimbra. Sednit also started to use a more recent vulnerability in Roundcube, CVE-2023-43770. The MDaemon vulnerability — CVE-2024-11182, now patched — was a zero day, most likely discovered by Sednit, while the ones for Horde, Roundcube, and Zimbra were already known and patched,' says ESET researcher Matthieu Faou, who discovered and investigated Operation RoundPress. Sednit sends these XSS exploits by email; the exploits lead to the execution of malicious JavaScript code in the context of the webmail client web page running in a browser window. Therefore, only data accessible from the target's account can be read and exfiltrated.
In order for the exploit to work, the target must be convinced to open the email message in the vulnerable webmail portal. This means that the email needs to bypass any spam filtering, and the subject line needs to be convincing enough to entice the target into reading the email message — abusing well-known news media such as Ukrainian news outlet Kyiv Post or Bulgarian news portal News.bg. Among the headlines used as spearphishing were: 'SBU arrested a banker who worked for enemy military intelligence in Kharkiv' and 'Putin seeks Trump's acceptance of Russian conditions in bilateral relations'.
The attackers unleash JavaScript payloads SpyPress.HORDE, SpyPress.MDAEMON, SpyPress.ROUNDCUBE, and SpyPress.ZIMBRA upon the targets. Those are capable of credential stealing; exfiltration of the address book, contacts, and log-in history; and exfiltration of email messages. SpyPress.MDAEMON is able to set up a bypass for two-factor authentication protection; it exfiltrates the two-factor authentication secret and creates an app password, which enables the attackers to access the mailbox from a mail application.
'Over the past two years, webmail servers such as Roundcube and Zimbra have been a major target for several espionage groups, including Sednit, GreenCube, and Winter Vivern. Because many organizations don't keep their webmail servers up to date, and because the vulnerabilities can be triggered remotely by sending an email message, it is very convenient for attackers to target such servers for email theft,' explains Faou.
The Sednit group — also known as APT28, Fancy Bear, Forest Blizzard, or Sofacy — has been operating since at least 2004. The U.S. Department of Justice named the group as one of those responsible for the Democratic National Committee (DNC) hack just before the 2016 U.S. elections and linked the group to the GRU. The group is also presumed to be behind the hacking of global television network TV5Monde, the World Anti-Doping Agency (WADA) email leak, and many other incidents.
For a more detailed analysis and technical breakdown of Sednit's tools used in Operation RoundPress, check out the latest ESET Research blogpost 'Operation RoundPress' on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.
About ESET
ESET® provides cutting-edge digital security to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of emerging global cyberthreats, both known and unknown — securing businesses, critical infrastructure, and individuals. Whether it's endpoint, cloud, or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. ESET technology includes robust detection and response, ultra-secure encryption, and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users safe and businesses running without interruption. The ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centers and a strong global partner network. For more information, visit www.eset.com or follow our social media, podcasts and blogs.
A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/eee3ee68-80dc-4136-a11d-6f498092f7d1
CONTACT: Media contact: Jessica Beffa Head of PR and Communications, North America jessica.beffa@eset.com (619) 876-5677
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles

Yahoo
15 minutes ago
- Yahoo
James Altucher: 'America Just Hit the AI Reset Button'
New briefing reveals how Trump and Musk are quietly building the most powerful artificial intelligence system in U.S. history — and why July 1 could mark a major turning point BALTIMORE, June 04, 2025 (GLOBE NEWSWIRE) -- In a new briefing, tech entrepreneur and bestselling author James Altucher reveals a development he says will 'change America forever.' At the center of it is Project Colossus — a classified supercomputer initiative led by Elon Musk's xAI — and backed by sweeping support from President Donald Trump. A Presidential Reversal with Massive Implications Altucher says the shift began with one of Trump's first presidential actions in 2025. 'In one of his FIRST acts as President… Donald Trump overturned Executive Order #14110.' This decision reversed Biden-era restrictions on AI research, which Altucher claims had 'prevented us from unleashing its true power.' 'Trump also announced the LARGEST AI investment in history… Stargate… a massive, AI data center and infrastructure project.' Hidden Inside a Warehouse in Memphis Altucher's report reveals a facility in Tennessee that, until now, has gone largely unnoticed. 'Right here, inside this warehouse in Memphis, Tennessee… lies a massive supercomputer Musk calls 'Project Colossus.'' 'It contains not just one or two… but 200,000 units of Nvidia's all-powerful AI chips… making it the most advanced AI facility known to man.' 'The fastest supercomputer on the planet.' — Jensen Huang, Nvidia CEO July 1: 'When It All Changes' According to Altucher, time is short. A critical update to Colossus is imminent. 'That's when I predict Elon could announce a major update to this new AI project. One that some say will essentially 10X its power – overnight.' Altucher refers to this moment as a 'second wave' of AI — what he calls: 'Artificial Superintelligence.' 'This second wave… will rival all of the great innovations of the past. Electricity… the wheel… even the discovery of fire.' A Warning… and a Milestone Altucher closes his briefing with a quote from Vladimir Putin to stress the stakes: 'Whoever becomes the leader in this sphere will become the ruler of the world.' — Vladimir Putin He believes Project Colossus may determine whether America leads — or falls behind — in the AI race. About James Altucher James Altucher is a computer scientist, entrepreneur, and bestselling author. A pioneer in AI since the 1980s, he previously worked on IBM's Deep Blue supercomputer and developed early AI trading systems on Wall Street. His latest research uncovers critical breakthroughs in AI infrastructure and the political forces accelerating its rise. Media Contact:Derek WarrenPublic Relations ManagerParadigm Press GroupEmail: dwarren@
Yahoo
an hour ago
- Yahoo
Skilled Immigrants are skipping the H-1B process and choosing faster paths to the Green Card
San Francisco, CA, June 04, 2025 (GLOBE NEWSWIRE) -- For many skilled professionals hoping to live and work in the United States, EB1A Experts know that the H-1B visa has long been the most familiar route. But these days, it's less of a clear path and more of a gamble. A lottery-based selection process, employer dependence, and long delays in getting permanent residency have made the journey frustrating and worrying for some. At this point of time, the need of the hour for skilled professionals is to look beyond this traditional route to secure a standard path to work and thrive in the United States. H-1B by the Numbers In 2024, the U.S. received 758,994 eligible registrations for the lottery. Still, only 65,000 visas were available under the regular cap, and another 20,000 were set aside for those with a U.S. master's degree or higher. That left more than 85% of applicants without a way challenges aren't over even for those who make it through the lottery. H-1B workers are legally tied to their sponsoring employers. Changing jobs requires paperwork, risk, and sometimes a process restart. When applying for a green card, the wait in categories like EB2 or EB3 can stretch across a decade or more, especially for Indian and Chinese professionals with solid careers and long-term goals, the H-1B route feels increasingly out of step with reality. A Better Option: The EB1A Green Card The EB1A green card is for individuals with substantial achievements in their fields. That could mean industry recognition, influential work, published research, leadership roles, or any combination. While it was once seen as an elite category for award winners or global figures, it's now accessible to more people than ever, especially in high-growth fields like AI, engineering, and data biggest difference? EB1A doesn't require employer sponsorship. Applicants can file independently. The process is also faster, with many receiving decisions swiftly. When premium processing is used. And the criteria, though rigorous, are clearly outlined. You have a shot if you meet at least three out of short, it's a path that rewards merit, not randomness. Why is this shift happening now There are a few reasons why more professionals are moving toward EB1A instead of waiting on H-1B or green card queues: The H-1B lottery is unpredictable, and getting selected is far from guaranteed. Green card backlogs are growing, with no apparent signs of policy reform in the short term. Skilled workers are building stronger profiles — leading major projects, publishing, and gaining recognition in ways that align with EB1A standards. More information and support are available, making the EB1A process less intimidating and achievable. This isn't just a workaround — it's a more innovative strategy that more professionals are beginning to understand. The Role of EB1A Experts One company helping lead this shift is EB1A Experts, a service that focuses exclusively on helping tech professionals prepare and apply for the EB1A green card. Instead of the existing generic approaches, the team uses a structured process supported by AI Turing, which evaluates each client's background against past USCIS approvals and identifies areas to model is designed around precision: matching each applicant's work to the proper EB1A criteria and building a clear, evidence-backed profile. Some key results: Over 92% approval rate Criteria specific teams End-to-end profile-building support in the most comprehensive way The company doesn't promise shortcuts but offers structure, speed, and clarity in a process that's often confusing and overwhelming. What comes next As more skilled immigrants realize they don't have to stay stuck in the H-1B loop, the EB1A pathway is becoming more than just an alternative—it's a first choice. This shift reflects a broader shift in how global talent approaches U.S. immigration: not as something left to chance but as a process that can be managed strategically. The demand for faster, flexible options will only grow. Professionals who understand their options early will have an edge, not just in how they build their careers but also in how they shape their lives in the U.S. CONTACT: Shazir Mucklai Imperium AI 2144225414 shazir at while retrieving data Sign in to access your portfolio Error while retrieving data Error while retrieving data Error while retrieving data Error while retrieving data


Boston Globe
3 hours ago
- Boston Globe
As activists accuse Kraft campaign of breaking election law, Kraft campaign alleges violations by Wu
The flurry of allegations comes amid an increasingly expensive and Advertisement The allegations related to the Kraft campaign center on Jonathan Karush, a political operative with a leadership role in organizations that are working for both the Kraft campaign and the super PAC. Super PACs are independent spending groups that can raise and spend unlimited money, but may not coordinate directly or indirectly with the campaigns or candidates themselves. In the wake of Advertisement Karush is the president of Additionally, Karush is a principal owner of CP Campaigns LLC, which performs digital ad buying work for the Kraft-aligned super PAC. The PAC has reported paying CP Campaigns $425,000 so far. The company has existed only since March of this year, state business records show. Karush said in an email to the Globe that he 'has no personal involvement with the operations of the super PAC.' 'There is a firewall put in place to any engagement to ensure compliance with Massachusetts election law,' he said in the email. He did not respond to Globe questions about who at CP Campaigns is performing work on behalf of the super PAC, nor a request for a copy of any written 'firewall' policy. O'Connor, a spokesperson for the Kraft campaign, said in a statement that Karush is a 'subcontractor' 'not an employee,' at Keyser Public Strategies, and said his work on the Kraft campaign is 'limited to website and digital/graphic work — non-strategic activities which will be reflected in public filings.' State Advertisement Geoff Foster, executive director of the good government group Common Cause Massachusetts, said the close ties between the organizations working for the Kraft campaign and the Kraft-aligned PAC raise 'important questions about what firewalls are actually in place.' State officials should quickly, thoroughly investigate any credible claims of wrongdoing, Foster said. Asked about the Kraft campaign allegations that public employees are improperly working on the Wu campaign, Foster noted that there are important conflict of interest laws in place regulating what public employees may do on political campaigns. 'There's a need for OCPF to be the referee in the ring right now,' Foster added. The Kraft campaign on Wednesday asked OCPF to launch an investigation into Wu for a litany of alleged violations, including what it said was 'impermissible coordination' between Wu's campaign and a super PAC in 2021, when she first ran for mayor. The Kraft campaign also alleged that Wu is improperly relying on City Hall staff to perform the work of her political campaign. In Massachusetts, public employees are permitted to make political contributions and work on campaigns, but Advertisement The Kraft campaign claimed that members of the mayor's staff engaged in political activity during office hours and using public resources. Julia Leja, a spokesperson for Wu's campaign said the campaign is following the law and called the letter 'a transparent attempt to distract from illegal campaign spending by Josh Kraft and his Trump megadonors.' 'Boston voters will not be fooled,' she added. Emma Platoff can be reached at