TA458 is a threat actor tracked by Proofpoint, likely a Russian military intelligence operation. It conducts Operation RoundPress using half-click XSS exploits against webmail platforms (Zimbra, Kerio, SOGo, mDaemon, Roundcube) to deploy SpyPress malware, targeting Ukrainian government and Eastern European entities.