TA458 is a Russia-aligned cyberespionage threat actor responsible for Operation RoundPress, a campaign focused on exploiting webmail platforms to steal credentials, contacts, and sensitive email data. Its principal targets are Ukrainian government entities and government and military organizations in Eastern Europe, with documented targeting in Albania, Greece, Moldova, and Türkiye. It also occasionally targets chemical, telecommunications, and technology companies. TA458 delivers exploit-bearing messages through actor-controlled and compromised email accounts. Its half-click attacks exploit cross-site scripting vulnerabilities that execute malicious JavaScript when a recipient opens an email in a vulnerable webmail viewer, without requiring a link click or attachment execution. The actor deploys SpyPress, a JavaScript malware family adapted to Zimbra, MDaemon, Roundcube, Kerio, and SOGo. Its exploitation includes Zimbra CVE-2025-27915, MDaemon CVE-2025-3929, and SOGo CVE-2026-8496 as zero-days, alongside the previously disclosed Roundcube vulnerabilities CVE-2023-43770 and CVE-2024-42009. TA458 uses JavaScript obfuscation and proxy services to conceal aspects of its operations. Since at least July 2025, TA458 has extended its Roundcube operations beyond mailbox theft to persistent server compromise. It chains webmail exploitation with CVE-2025-49113, an unsafe PHP deserialization vulnerability, to achieve arbitrary code execution. Its Roundcube-focused SpyPress variant attempts six fallback persistence and backdoor mechanisms, including reverse shells, remote payload retrieval, and PHP webshells.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
In March 2026, the group exploited a zero-day flaw in SOGo webmail, later patched as CVE-2026-8496 in version 5.12.8.
SpyPress uses a second Roundcube exploit (CVE-2025-49113) that abuses Roundcube's file upload handler to trigger unsafe PHP deserialization. The end goal is to trigger arbitrary code execution and install multiple backdoor or persistence mechanisms.
Observed targets now span Zimbra (CVE-2025-27915), mDaemon (CVE-2025-3929), Roundcube (CVE-2024-42009, CVE-2023-43770), Kerio, and SOGo (CVE-2026-8496).
Observed targets now span Zimbra (CVE-2025-27915), mDaemon (CVE-2025-3929), Roundcube (CVE-2024-42009, CVE-2023-43770), Kerio, and SOGo (CVE-2026-8496).
Observed targets now span Zimbra (CVE-2025-27915), mDaemon (CVE-2025-3929), Roundcube (CVE-2024-42009, CVE-2023-43770), Kerio, and SOGo (CVE-2026-8496).
2 more CVEs tied to this actor tracked in Mallory.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exploiting the Half-click vulnerability in webmail platforms to harvest credentials, contacts, and emails and maintain persistence.
Acteurs de menace # ... TA458 (state-sponsored) ...
Conducting espionage-focused attacks against webmail platforms using half-click/XSS exploit chains to steal sensitive email data, including exploitation of a SOGo zero-day and use of SpyPress malware.
Russian military intelligence-linked activity cluster behind Operation RoundPress, targeting webmail platforms including Zimbra, Kerio, SOGo, mDaemon, and Roundcube using half-click XSS and other exploits to steal data and later establish long-term interactive backdoor access via SpyPress.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.