None
EN
Operation RoundPress
[]
WeLiveSecurity
This blogpost introduces an operation that we named RoundPress, targeting high-value webmail servers with XSS vulnerabilities, and that we assess with medium confidence is run by the Sednit cyberespionage group.
Key points of this blogpost: In Operation RoundPress, the compromise vector is a spearphishing email leveraging an XSS vulnerability to inject malicious JavaScript code into the victim’s webmail page.
Operation RoundPress compromise chainGenerally, the email message looks benign and contains text about news events.
Furthermore, strings used by the code, such as webmail and C&C server URLs, are also obfuscated and contained in an encrypted list.
The payload is fully contained in the email and only executed when the email message is viewed from a vulnerable webmail instance.
['roundpress'
'figure'
'victims'
'sednit'
'servers'
'xss'
'cc'
'spypressroundcube'
'targeting'
'operation'
'message'
'email'
'server'
'webmail'
'highvalue']