HomeSecurityHackers targeted government webmail - Greece also targeted

Hackers targeted government webmails – Greece also targeted

A well-organized cyber espionage campaign, codenamed "RoundPress," is sensitive emails from government organizations targeting . Cybercriminals are exploiting zero-day and n-day vulnerabilities in webmail servers to gain access to confidential correspondence.

Hackers targeted government webmail - Greece also targeted

According to a new report from ESET, the operation appears to be carried out by the APT group Fancy Bear (APT28), known for its support by Russian state actors. Researchers attribute the campaign to these hackers with a “moderate degree of certainty.”

The attackers' activity began in 2023 and continued with the use of new exploits targeting the Roundcube, Horde, MDaemon, and Zimbra.

See also: RedCurl hackers: They turn from espionage to ransomware

Among the targeted entities are the governments of Greece, Ukraine, Serbia and Cameroon, military units in Ukraine and Ecuador, defense industries in Ukraine, Bulgaria and Romania, as well as critical infrastructure in Ukraine and Bulgaria.

Minimum interaction, maximum damage

The attack begins with a spear-phishing email that appears to come from a trusted source and refers to current events or political developments. The messages often contain excerpts from real news articles, lending authenticity and reducing the recipient's suspicions.

The dangerous point is in the HTML body of the email, where a malicious JavaScript payload. This triggers an XSS (cross-site scripting) vulnerability in the webmail browser page used by the recipient. The most worrying thing is that it is enough to simply open the email. Then no further action is required from the user to execute the payload.

The script that is executed is designed to "fool" the user's browser or password manager , creating invisible input fields that trigger auto-fill of the stored email account credentials . Although there are no persistence mechanisms, the damage is done immediately, by collecting sensitive data and credentials.

See also: Scattered Spider hackers target US retail

Additionally, the malicious script interacts directly with the Document Object Model (DOM) and makes HTTP requests in order to steal data such as email contents, contact lists, account settings, login files, two-factor authentication (2FA), and saved passwords.

Once collected, the data is sent via HTTP POST requests to predefined Command and Control (C2) addresses.

Each malicious script is tailored to the target platform, featuring a specialized set of functions that allows it to fully exploit the features of the specific webmail.

What webmail vulnerabilities did the hackers exploit?

The RoundPress operation focuses on XSS (Cross-Site Scripting) vulnerabilities found in popular webmail products widely used by government and business organizations. Through these security holes, hackers inject malicious JavaScript scripts.

government webmail hackers vulnerabilities

ESET published a series of vulnerabilities exploited in the campaign :

  • Roundcube – CVE-2020-35730: A stored XSS vulnerability, through which attackers could inject malicious JavaScript directly into the body of an email. When the message was viewed via a browser-based webmail session, the script would automatically execute, stealing credentials and other data.
  • Roundcube – CVE-2023-43770: Vulnerability in the way the platform handled hyperlinks. The lack of proper sanitization allowed the introduction of <script> tags μέσα στο περιεχόμενο των email, οδηγώντας σε άμεση εκτέλεση JavaScript κατά την προβολή του email.
  • MDaemon – CVE-2024-11182 : A zero-day XSS vulnerability in the HTML parser of MDaemon Email Server. Attackers crafted specially crafted messages with forged HTML attributes and noembed tags , successfully loading JavaScript. The result was the interception of credentials, bypassing 2FA mechanisms, and establishing permanent access via application-specific passwords.
  • Horde – Unknown XSS: APT28 attempted to exploit an old XSS vulnerability in Horde by placing a script in <img onerror> handler However, the attempt failed, likely due to the built-in filtering in modern Horde versions. The exact flaw is not confirmed, but it appears to have been patched in the meantime.
  • Zimbra – CVE-2024-27443: An XSS vulnerability in Zimbra's calendar invite handling. Unsanitized input from the X-Zimbra-Calendar-Intended-For header allowed JavaScript to be injected into the calendar user interface. APT28 embedded a hidden script that decoded and executed JavaScript when the invite was displayed.

2025 without recorded activity – but not without risk

While ESET has not identified any new incidents directly related to the RoundPress in 2025, the techniques used in previous years remain highly relevant. With XSS vulnerabilities continuing to surface across a number of popular webmail platforms, the ground remains fertile for similar attacks if organizations do not strengthen their defenses.

See also: Turkish hackers exploited Output Messenger vulnerability

The RoundPress is a prime example of the increasing sophistication and targeting in the cyber espionage arena, especially when it comes to state-sponsored APT groups like APT28. What makes it particularly dangerous is not only the use of known and unknown XSS vulnerabilities in popular webmail platforms, but also the minimization of user interaction: simply opening an email can lead to a serious breach.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS