Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458

    Date: 07/29/2026

    Severity: High

    Summary

    TA458, the Russia-aligned group behind Operation RoundPress, continues targeting webmail platforms with half-click exploits that compromise users simply by opening a malicious email. The campaign relies on advanced XSS vulnerabilities to steal sensitive email data without requiring clicks or social engineering. Believed to be linked to Russia's GRU, TA458 maintains a steady supply of webmail exploits, though their source remains unknown. In March 2026, the group exploited a zero-day flaw in SOGo webmail, later patched as CVE-2026-8496 in version 5.12.8. Its primary targets include Ukrainian government agencies and military organizations across Eastern Europe, with occasional attacks on chemical, telecom, and technology sectors. TA458 also continues using the SpyPress JavaScript malware, adapting it to different webmail platforms to support espionage and email theft.

    Indicators of Compromise (IOC) List  

    Domains/URLs

    share-ya.space

    xwe.us

    hgmydr.wiki

    xsza.net

    zxzaq.com

    Upgybj.store 

    Hash  

    625e4c166c7a1d5a1becf56b27d4f76a2f95935cbd8d556c30a493263d10dbf8

    a0c80cab70d6672b01710a70f93311fc1c1db2fbbf9cd6daa543c34b87e3444a

    fb8ec4dbed14c0a91361abd82ebe9fb083615c3dbb15348f57317af7cc41dd34

    3a449148a0e3cac604fb93210dd7d91ccf48e06ed9aae064bc53a419a84ce9ba

    8b5a4dc237a4c89042176bc89864a4c357dcdd14fa544fe6496ccb6c31cd5b7f

    6b2c02bf82087a3ca5fb7ef8046554ff29ce85d52202bdcfae2b2653aede139a

    e27d1bf82249002a66395c89dbda6ec5d8df012a84b79d36fffbbf7808d28878

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "zxzaq.com" or url like "zxzaq.com" or siteurl like "zxzaq.com" or domainname like "share-ya.space" or url like "share-ya.space" or siteurl like "share-ya.space" or domainname like "xwe.us" or url like "xwe.us" or siteurl like "xwe.us" or domainname like "hgmydr.wiki" or url like "hgmydr.wiki" or siteurl like "hgmydr.wiki" or domainname like "xsza.net" or url like "xsza.net" or siteurl like "xsza.net" or domainname like "upgybj.store" or url like "upgybj.store" or siteurl like "upgybj.store"

    Detection Query 2 :

    sha256hash IN ("fb8ec4dbed14c0a91361abd82ebe9fb083615c3dbb15348f57317af7cc41dd34","3a449148a0e3cac604fb93210dd7d91ccf48e06ed9aae064bc53a419a84ce9ba","625e4c166c7a1d5a1becf56b27d4f76a2f95935cbd8d556c30a493263d10dbf8","6b2c02bf82087a3ca5fb7ef8046554ff29ce85d52202bdcfae2b2653aede139a","a0c80cab70d6672b01710a70f93311fc1c1db2fbbf9cd6daa543c34b87e3444a","e27d1bf82249002a66395c89dbda6ec5d8df012a84b79d36fffbbf7808d28878","8b5a4dc237a4c89042176bc89864a4c357dcdd14fa544fe6496ccb6c31cd5b7f")

    Reference:    

    https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits                            


    Tags

    UkraineGovernment Services and FacilitiesDefense Industrial BaseEuropeChemicalCommunicationsInformation TechnologyMalwareVulnerabilityCVE-2026Zero-dayExploitSocial EngineeringRussia

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags