SpyPress.ROUNDCUBE is a malicious JavaScript payload used in ESET-tracked Operation RoundPress. It is injected into vulnerable Roundcube webmail instances via spearphishing emails that exploit XSS flaws in the webmail interface; the payload executes when the victim opens the malicious email in a vulnerable Roundcube portal. ESET reported Roundcube exploitation in 2023 and 2024, including CVE-2020-35730 and CVE-2023-43770. The broader campaign is assessed with medium confidence by ESET to be run by Sednit, also known as APT28, Fancy Bear, Forest Blizzard, and Sofacy, with the goal of stealing confidential data from selected email accounts. Observed targeting primarily involved governmental entities and defense-related organizations, especially in Eastern Europe and organizations connected to the war in Ukraine, with additional victims in Africa, Europe, and South America. Once deobfuscated, SpyPress.ROUNDCUBE is described as having functionality similar to SpyPress.MDAEMON: credential theft, exfiltration of the address book and the about page, exfiltration of emails, and creation of malicious Sieve rules. Some samples can log victims out and capture credentials when they reauthenticate through the legitimate login form, and some create Sieve rules that forward copies of incoming emails to an attacker-controlled address. The payload is obfuscated, uses randomized variable and function names, decrypts strings only when needed, lacks true persistence, and is reloaded whenever the victim reopens the malicious email. SpyPress payloads exfiltrate stolen data to hardcoded command-and-control servers via HTTP POST requests, typically with base64-encoded content. Reported SpyPress C2 infrastructure includes sqj[.]fr, tgh24[.]xyz, tuo[.]world, lsjb[.]digital, jiaw[.]shop, hfuu[.]de, raxia[.]top, rnl[.]world, hijx[.]xyz, and ikses[.]net.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Patch Roundcube to the latest release; the injection vector is a known Roundcube XSS CVE (e.g., CVE-2020-35730, CVE-2023-43770, CVE-2024-37383).
Patch Roundcube to the latest release; the injection vector is a known Roundcube XSS CVE (e.g., CVE-2020-35730, CVE-2023-43770, CVE-2024-37383).
Patch Roundcube to the latest release; the injection vector is a known Roundcube XSS CVE (e.g., CVE-2020-35730, CVE-2023-43770, CVE-2024-37383).
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SpyPress.ROUNDCUBE is the JavaScript payload injected into vulnerable Roundcube webmail instances. Once deobfuscated, it reveals similar functionalities to what is implemented in SpyPress.MDAEMON: credential stealing, exfiltration of the address book and the about page, exfiltration of emails, and malicious Sieve rules.
"The attackers unleash JavaScript payloads SpyPress.HORDE, SpyPress.MDAEMON, SpyPress.ROUNDCUBE, and SpyPress.ZIMBRA upon the targets."
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Hooks the input[name=_pass] field; if empty, attaches a change listener and waits for the victim to type. POSTs _user + _pass + parent .username to the C2.
SpyPress payloads try to steal webmail credentials by creating a hidden login form, to trick the browser and password managers into filling the credentials.
SpyPress payloads can log out users to entice them into entering their credentials in a fake login form.
Hooks the input[name=_pass] field; if empty, attaches a change listener and waits for the victim to type. POSTs _user + _pass + parent .username to the C2.
SpyPress payloads try to steal webmail credentials by creating a hidden login form, to trick the browser and password managers into filling the credentials.
SpyPress payloads collect and exfiltrate emails, from the victim’s mailbox.
SpyPress.MDAEMON adds a Sieve rule to forward any incoming email to an attacker-controlled email address.
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
JavaScript payload delivered via XSS in Roundcube webmail to steal credentials and exfiltrate mailbox data (address book/contacts/login history/email messages) accessible in the victim’s webmail session.
JavaScript payload for Roundcube that steals credentials, exfiltrates address book and emails, logs victims out to prompt credential reentry, and can create malicious Sieve forwarding rules for ongoing email theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.