🚨 🇷🇺 𝗡𝗘𝗪 𝗥𝗘𝗦𝗘𝗔𝗥𝗖𝗛: 𝗢𝗽𝗲𝗿𝗮𝘁𝗶𝗼𝗻 𝗥𝗼𝘂𝗻𝗱𝗶𝘀𝗵 - 𝗨𝗻𝗰𝗼𝘃𝗲𝗿𝗶𝗻𝗴 𝗮𝗻 𝗔𝗣𝗧𝟮𝟴 𝗥𝗼𝘂𝗻𝗱𝗰𝘂𝗯𝗲 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝗮𝘁𝗶𝗼𝗻 𝗧𝗼𝗼𝗹𝗸𝗶𝘁 𝗧𝗮𝗿𝗴𝗲𝘁𝗶𝗻𝗴 𝗨𝗸𝗿𝗮𝗶𝗻𝗲
During infrastructure analysis, we identified an exposed server hosting what appears to be a complete Roundcube exploitation toolkit linked to
#APT28 (
#FancyBear) operations.
Full technical analysis IOCs here 👇
hunt.io/blog/operation-round…
Key findings:
• Open directory exposed 61 files across 36 directories containing payloads, tooling, and operator artifacts
• Toolkit targets Roundcube webmail for credential harvesting, mailbox exfiltration, and persistent mail forwarding
• 14 TTP overlaps with ESET's documented Operation RoundPress campaign
• Infrastructure targeting mail.dmsu(.)gov(.)ua (
#Ukraine State Migration Service)
• Toolkit includes a Flask C2 server, CSS side-channel module, and a Go Linux implant (httd)