Inside Operation RoundPress: How Fancy Bear Is Targeting Ukraine’s Allies with Sophisticated Email Espionage

Listen to this Post

Featured Image

Introduction:

A major cyber espionage campaign linked to the notorious Russian hacker group Fancy Bear is actively targeting organizations supporting Ukraine’s war efforts. Dubbed Operation RoundPress by cybersecurity firm ESET, this attack chain has been unfolding since at least 2023, evolving with new tactics and broader targets across multiple continents. The group’s strategy centers around exploiting vulnerabilities in popular webmail services to infiltrate accounts, steal sensitive data, and potentially disrupt military support operations. ESET’s recent report uncovers the technical details and geopolitical implications of this expansive cyber offensive, shedding light on how Russian-backed actors are weaponizing email servers to undermine global stability.

Operation RoundPress: Global Spyware Hidden in Emails

ESET’s investigation reveals that Operation RoundPress is a Kremlin-backed cyber espionage campaign attributed to the Russian hacker group Fancy Bear (also known as APT28). Launched as early as 2023, the campaign zeroes in on Ukrainian government bodies and defense contractors in Bulgaria and Romania, particularly those manufacturing Soviet-era weapons for Ukraine. The scope, however, is global — with targets identified in Africa, Europe, and South America.

The core attack method involves spearphishing emails that exploit cross-site scripting (XSS) vulnerabilities in widely used webmail platforms such as Roundcube, Horde, MDaemon, and Zimbra. By embedding malicious JavaScript into the body of an email, attackers can hijack the victim’s email session and steal credentials or access messages, even bypassing two-factor authentication.

Fancy Bear deploys multiple variants of this malware, dubbed SpyPress.HORDE, SpyPress.MDAEMON, SpyPress.ROUNDCUBE, and SpyPress.ZIMBRA. These payloads are tailored to exploit specific vulnerabilities in each mail platform. Some of the subject lines used in these malicious emails are designed to appear credible, borrowing headlines from real media sources like Kyiv Post and News.bg. Examples include sensational topics such as “SBU arrested a banker who worked for enemy military intelligence in Kharkiv” and “Putin seeks Trump’s acceptance of Russian conditions in bilateral relations.”

In 2023, the operation focused exclusively on Roundcube. By 2024, the group had expanded its reach, targeting newly discovered vulnerabilities like CVE-2024-11182 in MDaemon and older, unpatched issues in other platforms. ESET’s analysis of the JavaScript payloads shows that attackers can persist in a system for extended periods if not detected.

Fancy Bear has long been linked to the Russian military intelligence agency GRU, officially identified by the US as Unit 26165. Their high-profile attacks include the 2016 DNC email breach, the 2015 TV5Monde hack, and the WADA leaks. Their tactics continually evolve, with Operation RoundPress marking one of their most extensive espionage operations to date.

What Undercode Say:

Operation RoundPress is a clear demonstration of how cyber warfare has moved beyond battlefield disruption and into the realm of long-term intelligence gathering. This is not just about stealing data — it’s about controlling narratives, manipulating geopolitical strategies, and potentially delaying aid critical to Ukraine’s defense.

Fancy Bear’s methodical exploitation of email servers reveals the Achilles heel of many government and private-sector IT infrastructures: outdated systems with unresolved vulnerabilities. Despite the critical role of secure communications in modern warfare and diplomacy, many organizations are still using legacy software with weak patching protocols. This provides a low-cost, high-impact opportunity for threat actors.

The use of credible-sounding spearphishing subject lines indicates a psychological layer to the operation. It’s social engineering at its finest — designed to lure unsuspecting employees or officials into triggering malware that could compromise sensitive information. The blend of technical prowess and psychological manipulation makes Fancy Bear’s playbook particularly dangerous.

Moreover, the campaign’s targeting of weapon manufacturers in NATO-adjacent countries like Bulgaria and Romania highlights its strategic importance. It’s not just an attack on Ukraine — it’s an attempt to cripple the logistics and support chains feeding into the conflict.

Webmail servers, being accessible remotely, are ideal targets for espionage groups. They offer persistent access, low detection rates, and the ability to bypass more traditional endpoint protections. And as the campaign shows, even when vulnerabilities are known, the failure to patch them leaves a wide window open for exploitation.

The expansion from Roundcube to MDaemon, Horde, and Zimbra in 2024 is especially troubling. It suggests that Fancy Bear is investing in sustained access rather than opportunistic hits. They’re digging in for the long haul, ensuring that even if one vector is shut down, others remain operational.

ESET’s exposure of CVE-2024-11182 as a previously unknown zero-day exploited by the group should serve as a wake-up call. If Fancy Bear is capable of discovering and using zero-day flaws, this indicates a level of technical sophistication that rivals top-tier state actors. The group isn’t just relying on recycled hacks — they’re innovating.

The geopolitical reach of the campaign — spanning South America, Europe, and Africa — points to a broader Russian strategy. By gaining access to international diplomatic or defense-related communications, Russia can influence global perceptions and negotiations around the Ukraine war.

What’s also notable is the apparent absence of financial motives. This isn’t ransomware or banking malware. Fancy Bear is after information, influence, and control — the three pillars of state-sponsored cyber espionage.

To mitigate these threats, organizations must go beyond antivirus software and firewalls. Comprehensive email security, employee training, regular system updates, and endpoint detection and response (EDR) are now the frontline defense against state-sponsored cyber operations.

Operation RoundPress is a cyber wake-up call for governments and defense contractors worldwide. The question now isn’t whether your organization is being targeted — it’s whether you’ve already been compromised.

Fact Checker Results:

✅ Fancy Bear is confirmed by multiple intelligence agencies to be linked to Russia’s GRU
✅ ESET’s technical report on RoundPress provides credible, detailed analysis of JavaScript payloads
✅ CVE-2024-11182 is a legitimate zero-day vulnerability exploited in this campaign 🕵️‍♂️💻🔒

Prediction:

Operation RoundPress is unlikely to be the final act in Fancy Bear’s playbook. As global tensions continue, especially around NATO’s support for Ukraine, Russia’s cyber arsenal will likely become more aggressive and widespread. Expect more zero-day vulnerabilities to be discovered, with attacks expanding into sectors like energy, finance, and critical infrastructure. The digital battlefield is only heating up — and Fancy Bear is already several moves ahead.

References:

Reported By: www.infosecurity-magazine.com
Extra Source Hub:
https://www.github.com
Wikipedia
Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp | 💬 Telegram