Tag: Russia-Linked APT28

Russia-Linked APT28 Exploited MDaemon Zero Day to Hack Government Webmail Servers
News

Russia-Linked APT28 Exploited MDaemon Zero Day to Hack Government Webmail Servers

A cyber espionage campaign targeting webmail systems including Roundcube, Horde, MDaemon, and Zimbra via cross-site scripting (XSS) vulnerabilities, including a then-zero-day in MDaemon, has been traced to a threat actor with ties to Russia, according to new findings from ESET. The Slovak cybersecurity firm has called the activity, which started in 2023, Operation RoundPress. The Russian state-sponsored hacker collective known as APT28—also known as BlueDelta, Fancy Bear, Fighting Ursa, Forest Blizzard, FROZENLAKE, Iron Twilight, ITG05, Pawn Storm, Sednit, Sofacy, and TA422—has been credited with medium confidence with the hack. In a report provided to The Hacker News, ESET researcher Matthieu Faou stated that the ultimate objective of this operation is to acquire private informatio...