Date: 07/29/2026
Severity: High
Summary
TA458, the Russia-aligned group behind Operation RoundPress, continues targeting webmail platforms with half-click exploits that compromise users simply by opening a malicious email. The campaign relies on advanced XSS vulnerabilities to steal sensitive email data without requiring clicks or social engineering. Believed to be linked to Russia's GRU, TA458 maintains a steady supply of webmail exploits, though their source remains unknown. In March 2026, the group exploited a zero-day flaw in SOGo webmail, later patched as CVE-2026-8496 in version 5.12.8. Its primary targets include Ukrainian government agencies and military organizations across Eastern Europe, with occasional attacks on chemical, telecom, and technology sectors. TA458 also continues using the SpyPress JavaScript malware, adapting it to different webmail platforms to support espionage and email theft.
Indicators of Compromise (IOC) List
Domains/URLs | share-ya.space xwe.us hgmydr.wiki xsza.net zxzaq.com Upgybj.store |
Hash | 625e4c166c7a1d5a1becf56b27d4f76a2f95935cbd8d556c30a493263d10dbf8
a0c80cab70d6672b01710a70f93311fc1c1db2fbbf9cd6daa543c34b87e3444a
fb8ec4dbed14c0a91361abd82ebe9fb083615c3dbb15348f57317af7cc41dd34
3a449148a0e3cac604fb93210dd7d91ccf48e06ed9aae064bc53a419a84ce9ba
8b5a4dc237a4c89042176bc89864a4c357dcdd14fa544fe6496ccb6c31cd5b7f
6b2c02bf82087a3ca5fb7ef8046554ff29ce85d52202bdcfae2b2653aede139a
e27d1bf82249002a66395c89dbda6ec5d8df012a84b79d36fffbbf7808d28878
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "zxzaq.com" or url like "zxzaq.com" or siteurl like "zxzaq.com" or domainname like "share-ya.space" or url like "share-ya.space" or siteurl like "share-ya.space" or domainname like "xwe.us" or url like "xwe.us" or siteurl like "xwe.us" or domainname like "hgmydr.wiki" or url like "hgmydr.wiki" or siteurl like "hgmydr.wiki" or domainname like "xsza.net" or url like "xsza.net" or siteurl like "xsza.net" or domainname like "upgybj.store" or url like "upgybj.store" or siteurl like "upgybj.store" |
Detection Query 2 : | sha256hash IN ("fb8ec4dbed14c0a91361abd82ebe9fb083615c3dbb15348f57317af7cc41dd34","3a449148a0e3cac604fb93210dd7d91ccf48e06ed9aae064bc53a419a84ce9ba","625e4c166c7a1d5a1becf56b27d4f76a2f95935cbd8d556c30a493263d10dbf8","6b2c02bf82087a3ca5fb7ef8046554ff29ce85d52202bdcfae2b2653aede139a","a0c80cab70d6672b01710a70f93311fc1c1db2fbbf9cd6daa543c34b87e3444a","e27d1bf82249002a66395c89dbda6ec5d8df012a84b79d36fffbbf7808d28878","8b5a4dc237a4c89042176bc89864a4c357dcdd14fa544fe6496ccb6c31cd5b7f")
|
Reference:
https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits