The Russian hacking group Winter Vivern is exploiting a zero-day vulnerability in Roundcube Webmail and targeting European government entities and think tanks. The attacks have been ongoing since at least October 11.

The Roundcube development team has released security updates to fix the Stored Cross-Site Scripting (XSS) (CVE-2023-5631), reported by ESET researchers on October 16.
The security updates were released five days after the cybersecurity firm detected Russian cybercriminals using the Roundcube zero-day in attacks.
According to ESET 's findings , hackers used HTML email messages , which contained carefully crafted SVG documents , to remotely inject JavaScript code.
The phishing emails impersonated the Outlook team and attempted to trick potential victims into opening malicious emails. Upon opening, a first-stage payload was automatically activated, exploiting a vulnerability in the Roundcube email server.
See also: Rock County investigates ransomware attack
The final JavaScript payload used in the attacks helped malicious actors collect and steal emails . from compromised mail servers
“By sending a specially crafted email, attackers can load JavaScript code into the browser window. No manual intervention is required beyond viewing the message in a web browser,” ESET said.
The Winter Vivern hacking group was first detected in April 2021, and gained attention after it began targeting government agencies around the world, including countries such as India, Italy, Lithuania, Ukraine, and the Vatican.
See also: API vulnerabilities affected Grammarly, Vidio and Bukalapak
According to SentinelLabs, the group's goals align closely with the interests of the Belarusian and Russian.
Winter Vivern targets Zimbra and Roundcube email servers owned by government organizations, at least from 2022.

Theft of emails from government entities
The implications of government email theft are very serious and worrisome. First, such theft can cause significant damage to national security, as government communications contain sensitive information about defense strategy, politics, and diplomatic relations. Access to this information can allow hostile countries or groups to gain an advantage and cause irreparable damage to the security of the state.
See also: Hackers target Russian organizations with backdoor to steal data
Furthermore, the theft of government emails can have serious implications for public trust in government. Citizens trust the government to protect their personal information and the security of the state. When this trust is violated, citizens may question the government's ability to protect their interests.
Furthermore, the theft of government emails could have significant political implications. Russian hackers could use the stolen information to influence political decisions and elections in other countries. This could lead to the weakening of democratic processes and cause turmoil in international relations.
Finally, there are economic consequences. Hackers can use stolen information to conduct economic espionage, breach trade secrets, and steal commercial information. This can cause serious damage to the country's economy and threaten the competitiveness of businesses.
Source: www.bleepingcomputer.com
