Mail Server Hack: Old Exploit Used by Spies
- A hacking group, likely supported by the Russian government, has been actively exploiting cross-site scripting (XSS) vulnerabilities to compromise high-value mail servers worldwide.
- XSS vulnerabilities stem from coding errors in web server software.
- Security firm ESET reported that Sednit, a hacking group with ties to the Kremlin and known by names including APT28, Fancy Bear, Forest Blizzard, and Sofacy, gained unauthorized...
Russian Hackers Exploit XSS Vulnerabilities to Target Global Mail Servers
A hacking group, likely supported by the Russian government, has been actively exploiting cross-site scripting (XSS) vulnerabilities to compromise high-value mail servers worldwide. These attacks, reminiscent of those from decades past, have targeted organizations across multiple continents.
XSS vulnerabilities stem from coding errors in web server software. Attackers exploit these flaws to inject malicious code into the browsers of unsuspecting website visitors. The “samy Worm” attack on MySpace in 2005 brought XSS to the forefront, but such exploits have decreased in frequency in recent years, though they still occur.
Security firm ESET reported that Sednit, a hacking group with ties to the Kremlin and known by names including APT28, Fancy Bear, Forest Blizzard, and Sofacy, gained unauthorized access to email accounts. The group targeted mail server software from Roundcube, MDaemon, Horde, and Zimbra.
The most recent attacks focused on defense contractors in Bulgaria and Romania, some of which supply Soviet-era weaponry to Ukraine. Governmental bodies in those nations, as well as organizations in Africa, the European Union, and South America, were also targeted.
Dubbed “RoundPress” by ESET, the operation uses spearphishing emails to deliver XSS exploits.These exploits are concealed within the HTML code of the emails. In 2023, Sednit exploited CVE-2023-43770, a vulnerability in Roundcube that has since been patched. In the following year,the group exploited other XSS vulnerabilities in Horde,MDaemon,and Zimbra. One vulnerability in MDaemon was a zero-day exploit at the time of its use.
what’s next
Security experts advise organizations using the affected mail server software to ensure all patches are applied and to educate employees about the risks of spearphishing emails to mitigate future attacks exploiting XSS vulnerabilities.
