APT28, also known as Fancy Bear, exploited Roundcube webmail vulnerabilities to deploy the Roundish toolkit. This toolkit enabled credential harvesting, persistent mail forwarding, bulk email exfiltration, address book theft, and 2FA secret extraction from mail.dmsu.gov.ua.
Initial Access
Webmail Vulnerability Exploit
confirmed
APT28 exploited known Roundcube webmail vulnerabilities on mail.dmsu.gov.ua to gain initial access to the system.
Defender cut points
Implement regular vulnerability scanning and patching for web applications, especially open-source components like Roundcube.Enforce a robust web application firewall (WAF) to detect and block exploit attempts against known vulnerabilities.