Hunt.io Links Roundcube Exploitation Toolkit Targeting Ukraine to APT28

· Original article ↗

Summary

Hunt.io says an exposed server revealed a Roundcube exploitation toolkit it assesses with medium-high confidence is linked to APT28. The toolkit enables credential theft, mailbox exfiltration, forwarding-rule persistence, and browser credential theft.

Key points

  • Hunt.io found an exposed directory in January 2026 containing a Roundcube exploitation toolkit, C2 components, payloads, and operator artifacts.
  • The researchers assess with medium-high confidence that the activity aligns with APT28, citing 14 overlaps with ESET-documented Operation RoundPress.
  • Operator artifacts indicate targeting of mail.dmsu.gov.ua, Ukraine’s State Migration Service; the toolkit uses XSS and phishing to capture credentials and mailbox data.
  • Its capabilities include hidden-form password-manager capture, email and address-book theft, TOTP secret extraction, and Sieve rules that forward incoming mail to an external address.
  • A CSS side-channel module and Chrome and Firefox credential theft tools extend the toolkit beyond previously documented APT28 webmail activity.
  • A Go implant recovered from a compromised Ukrainian web application supports persistence through cron, systemd, and an SELinux policy mechanism.
  • Hunt.io recommends auditing external mail-forwarding rules, revoking sessions and resetting MFA secrets on compromised accounts, and monitoring for the identified implant and network indicators.

Article Details

Attack Vectors
  • Malicious emails trigger XSS payloads when opened in the targeted webmail interface, launching credential harvesting, mailbox collection, contact theft, MFA-secret extraction, and forwarding-rule creation.
  • A cloned webmail login page captures credentials and redirects visitors to a lure PDF.
  • Invisible autocomplete-enabled login fields capture browser password-manager autofill values when the victim clicks the page.
  • Server-side mail forwarding provides continued email exfiltration after password changes, session revocation, or vulnerability patching.
  • CSS selector matching and chained imports progressively leak DOM attribute values through external callbacks; the researchers assess that CSRF tokens or email UIDs are likely targets.
  • Browser credential collection includes a PowerShell-based delivery chain and server-side decryption of stolen encrypted credentials.
  • Operator history records SSH pivoting, reverse-shell deployment, payload staging, and container-environment checks.
  • A recovered Linux implant supports cron and service persistence and loads a custom security-policy module to permit its execution.
Defensive Notes
  • Audit and remove unauthorized Sieve and ManageSieve forwarding rules; password resets alone do not stop server-side forwarding.
  • For compromised accounts, revoke and re-enroll MFA credentials, invalidate sessions, and verify that no unauthorized forwarding filters remain.
  • Apply webmail security updates and enforce a strict Content Security Policy blocking eval(), inline scripts, and untrusted external resources.
  • Disable ManageSieve when forwarding is not a business requirement.
  • Monitor outbound SMTP for unexpected external forwarding, HTTP requests during email rendering, chained CSS imports with incrementing parameters, and bulk viewsource API requests.
  • Look for the /zJ2w9x?log= URI pattern and the custom HTTP header secure: bigdick.
  • Inspect /etc/crontab for /.img, /boot for linux.service, and installed SELinux modules for my-Systemimgconf; block the recovered implant hash.

Indicators of compromise

TypeIndicatorContext
DOMAINzhblz[.]comUndefanged primary C2 domain appearing in captions and exfiltration descriptions.
EMAILadvenwolf@proton[.]meUndefanged forwarding destination used to receive victims' incoming email.
EMAILsrezoska@skiff[.]comMalicious forwarding destination documented for the compared SpyPress activity.
HOSTNAMEa[.]zhblz[.]comUndefanged CSS side-channel hostname used for /leak and /end callbacks.
HOSTNAMEblog[.]pentagonteam[.]comUndefanged hostname of the compromised web application whose recovered archive contained the httd implant.
HOSTNAMEdocs[.]goog1e[.]com[.]spreadsheets[.]d[.]1ipevana4hglaeksstshboujdk[.]zhblz[.]comC2-associated hostname mimicking Google Spreadsheets URLs for credential phishing.
IPV4130[.]61[.]233[.]105Operator infrastructure identified as a long-standing SSH pivot host on Oracle Cloud.
IPV4203[.]161[.]50[.]145Undefanged C2 hosting address explicitly shown in infrastructure figure captions.
MD54b3e139c122df9fbc08442b7823ebde9MD5 of the recovered httd Go ELF backdoor.
SHA256e76f54b7b98ba3a08f39392e6886a9cb3e97d57b8a076e6b948968d0be392ed8SHA-256 of the recovered httd Go ELF backdoor.

MITRE ATT&CK

T1021.004 · SSHOperator history records SSH connections to an Oracle Cloud pivot host and a secondary SSH target.T1027 · Obfuscated Files or InformationThe production worklast.js payload uses shuffled string arrays, computed indexes, and a self-modifying rotation function.T1036.005 · Match Legitimate Resource Name or LocationPayload artifacts use names such as snmpd.elf and httd, and operator history suggests masquerading a payload as e2scrub_all.T1041 · Exfiltration Over C2 ChannelThe Flask C2 receives stolen email files, browser credential databases, credentials, contacts, and TOTP secrets over HTTP endpoints.T1053.003 · CronStrings in httd show creation of a root cron entry executing /.img every minute.T1056.003 · Web Portal CaptureA cloned Roundcube login portal captures submitted credentials; injected hidden login fields also harvest autofilled credentials.T1059.001 · PowerShellBrowser.ps1 collects Chrome credential data for server-side decryption.T1059.007 · JavaScriptThe XSS payload fetches JavaScript collection modules and executes them through eval().T1087.003 · Email AccountThe adbook.js module extracts the victim's complete address book.T1111 · Multi-Factor Authentication InterceptionThe keyTwoAuth.js module extracts and exfiltrates TOTP secrets from accounts with two-factor authentication enabled.T1114.002 · Remote Email CollectionThe downd() function collects every Inbox and Sent message as an .eml file through Roundcube's viewsource API.T1114.003 · Email Forwarding RuleThe payload creates a Sieve rule redirecting incoming messages to the operator's ProtonMail dead drop.T1190 · Exploit Public-Facing ApplicationThe toolkit exploits XSS in Roundcube to execute malicious payloads in victims' webmail sessions.T1543.002 · Systemd ServiceStrings in httd show enabling and starting linux.service from /boot; operator history also records a payload service file.T1555.003 · Credentials from Web BrowsersThe toolkit collects Chrome encrypted credential data and Firefox logins.json and key4.db; the C2 decrypts Chrome entries using the stolen key.T1562.001 · Disable or Modify ToolsStrings in httd show generating and loading a custom SELinux policy module with audit2allow and semodule to whitelist its execution.T1566.002 · Spearphishing LinkThe article identifies a cloned webmail login page, lure PDF, and Google Spreadsheets-lookalike hostname used for credential phishing.T1583.001 · DomainsThe primary C2 domain and dedicated CSS-extraction subdomain were registered for operational infrastructure.T1595 · Active ScanningOperator history records connectivity reconnaissance against the targeted webmail host and port scanning with RustScan.T1613 · Container and Resource DiscoveryA recovered script checks privileged mode, Docker sockets, host PID exposure, Linux capabilities, and container security profiles.

People

Threat Actors

Malware

Vendors

Products

Google ChromeBrowser credential stealers Not documented Chrome AES-GCM + Firefox NEWHordeOver the past two years, APT28 has systematically targeted webmail platforms, including Roundcube, Horde, MDaemon, and Zimbra, through XSS vulnerabilities to steal credentials, emails, and contacts from government andMDaemonOver the past two years, APT28 has systematically targeted webmail platforms, including Roundcube, Horde, MDaemon, and Zimbra, through XSS vulnerabilities to steal credentials, emails, and contacts from government andMozilla FirefoxBrowser credential stealers Not documented Chrome AES-GCM + Firefox NEWNext.jsarchive containing the complete source code, Git repository, and environment configuration of a Next.js web application for blog.pentagonteam.com. This is not an attacker tool; it is exfiltrated victim data.OpenSSHhosted on Oracle Corporation infrastructure (AS31898) in Frankfurt, Germany. This host runs OpenSSH 9.6p1 on Ubuntu Linux and exposes ports 22, 80, 443, and 6001. The SSH service has been active sincePA-450The running-config.xml file on the C2 server is a complete Palo Alto Networks PA-450 next-generation firewall configuration from 106.51.89[.]49, belonging to Atria Convergence Technologies (ACT Fibernet, AS24309) inRoundcubehas repeatedly targeted webmail platforms to gain access to government and defense email accounts. Roundcube, in particular, has appeared in multiple campaigns due to its widespread deployment and history ofUbuntu Linuxon Oracle Corporation infrastructure (AS31898) in Frankfurt, Germany. This host runs OpenSSH 9.6p1 on Ubuntu Linux and exposes ports 22, 80, 443, and 6001. The SSH service has been active since December 2022,Zimbratwo years, APT28 has systematically targeted webmail platforms, including Roundcube, Horde, MDaemon, and Zimbra, through XSS vulnerabilities to steal credentials, emails, and contacts from government and defense

Tools

Countries

Industries

Related Articles