CyberSecurityBoardThreat Intel · CVEs · Products
Attack Groups

TA458: Russian Military Intelligence Operation Targeting Webmail

July 24, 2026

TA458 is a threat actor tracked by Proofpoint, likely a Russian military intelligence operation. It conducts Operation RoundPress using half-click XSS exploits against webmail platforms (Zimbra, Kerio, SOGo, mDaemon, Roundcube) to deploy SpyPress malware, targeting Ukrainian government and Eastern European entities.