216.73.216.6

Operation Roundish: Uncovering an APT28 Roundcube Exploitation Toolkit Targeting Ukraine

· Published 18/03/2026 10:51 · Modified 18/03/2026 11:20

Export JSON

Essential information

Published
18/03/2026 10:51
Modified
18/03/2026 11:20
Tags
2026-03-18 apt28 credential-theft css injection fancy bear go implant government httd roundcube spypress.roundish ukraine webmail xss
Related entities
5 observables, 1 intrusion sets (apt), 20 techniques (mitre), 2 malware, 8 others

Description

An exposed open directory revealed a comprehensive exploitation toolkit used by to target Ukrainian entities. The toolkit includes payloads, a Flask-based C2 server, tools, and a Go-based implant. It enables credential harvesting, persistent mail forwarding, bulk email exfiltration, address book theft, and 2FA secret extraction. The primary target was identified as mail.dmsu.gov.ua, 's State Migration Service. Technical analysis shows significant overlaps with previously documented operations, while introducing new capabilities such as CSS-based side-channel attacks and browser credential theft. The toolkit's modular approach and sophisticated evasion techniques demonstrate 's evolving tactics in compromising platforms for long-term intelligence gathering.

External references