Hunt.io Links Roundcube Exploitation Toolkit Targeting Ukraine to APT28

Summary
Hunt.io says an exposed server revealed a Roundcube exploitation toolkit it assesses with medium-high confidence is linked to APT28. The toolkit enables credential theft, mailbox exfiltration, forwarding-rule persistence, and browser credential theft.
Key points
- Hunt.io found an exposed directory in January 2026 containing a Roundcube exploitation toolkit, C2 components, payloads, and operator artifacts.
- The researchers assess with medium-high confidence that the activity aligns with APT28, citing 14 overlaps with ESET-documented Operation RoundPress.
- Operator artifacts indicate targeting of mail.dmsu.gov.ua, Ukraine’s State Migration Service; the toolkit uses XSS and phishing to capture credentials and mailbox data.
- Its capabilities include hidden-form password-manager capture, email and address-book theft, TOTP secret extraction, and Sieve rules that forward incoming mail to an external address.
- A CSS side-channel module and Chrome and Firefox credential theft tools extend the toolkit beyond previously documented APT28 webmail activity.
- A Go implant recovered from a compromised Ukrainian web application supports persistence through cron, systemd, and an SELinux policy mechanism.
- Hunt.io recommends auditing external mail-forwarding rules, revoking sessions and resetting MFA secrets on compromised accounts, and monitoring for the identified implant and network indicators.
Article Details
- Attack Vectors
- Malicious emails trigger XSS payloads when opened in the targeted webmail interface, launching credential harvesting, mailbox collection, contact theft, MFA-secret extraction, and forwarding-rule creation.
- A cloned webmail login page captures credentials and redirects visitors to a lure PDF.
- Invisible autocomplete-enabled login fields capture browser password-manager autofill values when the victim clicks the page.
- Server-side mail forwarding provides continued email exfiltration after password changes, session revocation, or vulnerability patching.
- CSS selector matching and chained imports progressively leak DOM attribute values through external callbacks; the researchers assess that CSRF tokens or email UIDs are likely targets.
- Browser credential collection includes a PowerShell-based delivery chain and server-side decryption of stolen encrypted credentials.
- Operator history records SSH pivoting, reverse-shell deployment, payload staging, and container-environment checks.
- A recovered Linux implant supports cron and service persistence and loads a custom security-policy module to permit its execution.
- Defensive Notes
- Audit and remove unauthorized Sieve and ManageSieve forwarding rules; password resets alone do not stop server-side forwarding.
- For compromised accounts, revoke and re-enroll MFA credentials, invalidate sessions, and verify that no unauthorized forwarding filters remain.
- Apply webmail security updates and enforce a strict Content Security Policy blocking eval(), inline scripts, and untrusted external resources.
- Disable ManageSieve when forwarding is not a business requirement.
- Monitor outbound SMTP for unexpected external forwarding, HTTP requests during email rendering, chained CSS imports with incrementing parameters, and bulk viewsource API requests.
- Look for the /zJ2w9x?log= URI pattern and the custom HTTP header secure: bigdick.
- Inspect /etc/crontab for /.img, /boot for linux.service, and installed SELinux modules for my-Systemimgconf; block the recovered implant hash.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | zhblz[.]com | Undefanged primary C2 domain appearing in captions and exfiltration descriptions. |
advenwolf@proton[.]me | Undefanged forwarding destination used to receive victims' incoming email. | |
srezoska@skiff[.]com | Malicious forwarding destination documented for the compared SpyPress activity. | |
| HOSTNAME | a[.]zhblz[.]com | Undefanged CSS side-channel hostname used for /leak and /end callbacks. |
| HOSTNAME | blog[.]pentagonteam[.]com | Undefanged hostname of the compromised web application whose recovered archive contained the httd implant. |
| HOSTNAME | docs[.]goog1e[.]com[.]spreadsheets[.]d[.]1ipevana4hglaeksstshboujdk[.]zhblz[.]com | C2-associated hostname mimicking Google Spreadsheets URLs for credential phishing. |
| IPV4 | 130[.]61[.]233[.]105 | Operator infrastructure identified as a long-standing SSH pivot host on Oracle Cloud. |
| IPV4 | 203[.]161[.]50[.]145 | Undefanged C2 hosting address explicitly shown in infrastructure figure captions. |
| MD5 | 4b3e139c122df9fbc08442b7823ebde9 | MD5 of the recovered httd Go ELF backdoor. |
| SHA256 | e76f54b7b98ba3a08f39392e6886a9cb3e97d57b8a076e6b948968d0be392ed8 | SHA-256 of the recovered httd Go ELF backdoor. |
MITRE ATT&CK
T1021.004 · SSHOperator history records SSH connections to an Oracle Cloud pivot host and a secondary SSH target.T1027 · Obfuscated Files or InformationThe production worklast.js payload uses shuffled string arrays, computed indexes, and a self-modifying rotation function.T1036.005 · Match Legitimate Resource Name or LocationPayload artifacts use names such as snmpd.elf and httd, and operator history suggests masquerading a payload as e2scrub_all.T1041 · Exfiltration Over C2 ChannelThe Flask C2 receives stolen email files, browser credential databases, credentials, contacts, and TOTP secrets over HTTP endpoints.T1053.003 · CronStrings in httd show creation of a root cron entry executing /.img every minute.T1056.003 · Web Portal CaptureA cloned Roundcube login portal captures submitted credentials; injected hidden login fields also harvest autofilled credentials.T1059.001 · PowerShellBrowser.ps1 collects Chrome credential data for server-side decryption.T1059.007 · JavaScriptThe XSS payload fetches JavaScript collection modules and executes them through eval().T1087.003 · Email AccountThe adbook.js module extracts the victim's complete address book.T1111 · Multi-Factor Authentication InterceptionThe keyTwoAuth.js module extracts and exfiltrates TOTP secrets from accounts with two-factor authentication enabled.T1114.002 · Remote Email CollectionThe downd() function collects every Inbox and Sent message as an .eml file through Roundcube's viewsource API.T1114.003 · Email Forwarding RuleThe payload creates a Sieve rule redirecting incoming messages to the operator's ProtonMail dead drop.T1190 · Exploit Public-Facing ApplicationThe toolkit exploits XSS in Roundcube to execute malicious payloads in victims' webmail sessions.T1543.002 · Systemd ServiceStrings in httd show enabling and starting linux.service from /boot; operator history also records a payload service file.T1555.003 · Credentials from Web BrowsersThe toolkit collects Chrome encrypted credential data and Firefox logins.json and key4.db; the C2 decrypts Chrome entries using the stolen key.T1562.001 · Disable or Modify ToolsStrings in httd show generating and loading a custom SELinux policy module with audit2allow and semodule to whitelist its execution.T1566.002 · Spearphishing LinkThe article identifies a cloned webmail login page, lure PDF, and Google Spreadsheets-lookalike hostname used for credential phishing.T1583.001 · DomainsThe primary C2 domain and dedicated CSS-extraction subdomain were registered for operational infrastructure.T1595 · Active ScanningOperator history records connectivity reconnaissance against the targeted webmail host and port scanning with RustScan.T1613 · Container and Resource DiscoveryA recovered script checks privileged mode, Docker sockets, host PID exposure, Linux capabilities, and container security profiles.
People
Threat Actors
APT28Hunt.io assesses with medium-high confidence that the recovered activity aligns with this group, citing technical overlaps with previously documented webmail operations. The article identifies Sednit, Fancy Bear, Forest Blizzard, FROZENLAKE, Iron Twilight, ITG05, Pawn Storm, and Sofacy as aliases.Fancy BearExplicitly identified as an alias of APT28, to which Hunt.io attributes the recovered activity with medium-high confidence.IRON TWILIGHTExplicitly identified as an alias of APT28, to which Hunt.io attributes the recovered activity with medium-high confidence.
Malware
httdA Go-based Linux implant (httd) found in a compromised environment provides persistence via cron, systemd, and SELinux.Meterpreterdirectly on the C2 server. Directories named test/testnew/z/ and AAAA/ served as staging areas for Meterpreter payloads. Custom shell scripts (q.sh, q80.sh, q443.sh) served as quick-launch wrappers for reverseSpyPressautofill through invisible forms, is not common in general-purpose XSS toolkits. Its presence in both SpyPress and Roundish strongly suggests a shared developer or development playbook.SpyPress.MDAEMONThe third major overlap is two-factor authentication extraction. SpyPress.MDAEMON's documented ability to exfiltrate TOTP secrets and create application passwords for MFA bypass is directly mirrored by Roundish'sSpyPress.Roundishwith @import chaining and CSS selector matching against rcmbtnfrm100 href attributes.XSS payload: SpyPress.Roundish
Vendors
NamecheapDuring our threat hunting, we found an open directory on 203.161.50[.]145, hosted on Namecheap infrastructure (AS22612) in Phoenix, Arizona. The server exposed port 8889 with a Python SimpleHTTP directory listingOracleBash history reveals SSH connections to 130.61.233[.]105, hosted on Oracle Corporation infrastructure (AS31898) in Frankfurt, Germany. This host runs OpenSSH 9.6p1 on Ubuntu Linux and exposes ports 22, 80, 443, andPalo Alto NetworksThe running-config.xml file on the C2 server is a complete Palo Alto Networks PA-450 next-generation firewall configuration from 106.51.89[.]49, belonging to Atria Convergence Technologies (ACT Fibernet, AS24309) inProtonMailcreates an identical forwarding rule but targets advenwolf@proton.me. The shift from Skiff to ProtonMail is operationally logical: Skiff was acquired by Notion in February 2024 and subsequently discontinuedSupermicroThe presence of IPMICFG.efi, Supermicro's IPMI Configuration Utility for UEFI environments, indicates the operator has access to bare-metal server infrastructure with baseboard management controllers. IPMI provides
Products
Google ChromeBrowser credential stealers Not documented Chrome AES-GCM + Firefox NEWHordeOver the past two years, APT28 has systematically targeted webmail platforms, including Roundcube, Horde, MDaemon, and Zimbra, through XSS vulnerabilities to steal credentials, emails, and contacts from government andMDaemonOver the past two years, APT28 has systematically targeted webmail platforms, including Roundcube, Horde, MDaemon, and Zimbra, through XSS vulnerabilities to steal credentials, emails, and contacts from government andMozilla FirefoxBrowser credential stealers Not documented Chrome AES-GCM + Firefox NEWNext.jsarchive containing the complete source code, Git repository, and environment configuration of a Next.js web application for blog.pentagonteam.com. This is not an attacker tool; it is exfiltrated victim data.OpenSSHhosted on Oracle Corporation infrastructure (AS31898) in Frankfurt, Germany. This host runs OpenSSH 9.6p1 on Ubuntu Linux and exposes ports 22, 80, 443, and 6001. The SSH service has been active sincePA-450The running-config.xml file on the C2 server is a complete Palo Alto Networks PA-450 next-generation firewall configuration from 106.51.89[.]49, belonging to Atria Convergence Technologies (ACT Fibernet, AS24309) inRoundcubehas repeatedly targeted webmail platforms to gain access to government and defense email accounts. Roundcube, in particular, has appeared in multiple campaigns due to its widespread deployment and history ofUbuntu Linuxon Oracle Corporation infrastructure (AS31898) in Frankfurt, Germany. This host runs OpenSSH 9.6p1 on Ubuntu Linux and exposes ports 22, 80, 443, and 6001. The SSH service has been active since December 2022,Zimbratwo years, APT28 has systematically targeted webmail platforms, including Roundcube, Horde, MDaemon, and Zimbra, through XSS vulnerabilities to steal credentials, emails, and contacts from government and defense
Tools
IPMICFG.efiIPMICFG.efiLigolo-ngIP profile for 203.161.50[.]145 showing open ports, Roundcube on port 443, Flask/Werkzeug on port 5000, Ligolo-ng tunneling on port 11601, and Possible APT: APT28 classification.The server hosts seven distinctMetasploit FrameworkThe operator's bash history provides an unusually detailed look at their post-exploitation workflow. Metasploit Framework is the primary tool for generating payloads targeting compromised Linux hosts.msfvenomFigure 22. Bash history showing msfvenom payload generation with C2 callback to 203.161.50[.]145, multiple payload variants (krp, krpb), and Python HTTP servers for staging.The bash history reveals the operator managingRoundishRoundish introduces additional components not previously documented in APT28 webmail activity, including a CSS-based side-channel module and browser credential theft capabilities.rustscandirectly: the operator created a senderRB/ directory and ran curl mail.dmsu.gov.ua to test connectivity. RustScan was used for port scanning reconnaissance. The operator archived the toolkit with tar -czvf
Countries
GermanySSH connections to 130.61.233[.]105, hosted on Oracle Corporation infrastructure (AS31898) in Frankfurt, Germany. This host runs OpenSSH 9.6p1 on Ubuntu Linux and exposes ports 22, 80, 443, and 6001. The SSH serviceIndiafrom 106.51.89[.]49, belonging to Atria Convergence Technologies (ACT Fibernet, AS24309) in Bengaluru, India. This ISP serves residential and enterprise broadband customers across southern India.RussiaIron Twilight, ITG05, Pawn Storm, and Sofacy, has been operating since at least 2004 and is attributed to Russia's GRU military intelligence service. The US Department of Justice named the group as one of thoseUkrainethrough bash history and infrastructure analysis is mail.dmsu.gov.ua, the Roundcube webmail instance of Ukraine's State Migration Service (DMSU). The operator's bash history shows direct reconnaissance with curl
Industries
Defensefew years, APT28 (Fancy Bear) has repeatedly targeted webmail platforms to gain access to government and defense email accounts. Roundcube, in particular, has appeared in multiple campaigns due to its widespreadGovernmentOver the past few years, APT28 (Fancy Bear) has repeatedly targeted webmail platforms to gain access to government and defense email accounts. Roundcube, in particular, has appeared in multiple campaigns due to itsTelecommunications