Half-Click, Full Compromise: Inside Russia's TA458 and TA488 Espionage Playbook
Show notes
Hello to all our cyber roosters!
Host Selena Larson is joined by co-host Sarah Sabatka and returning guest Greg Lesnewich, Principal Threat Researcher at Proofpoint, to unpack two new reports on Russian aligned espionage actors abusing “half-click” exploits, which are vulnerabilities that compromise a target the moment they open an email in a vulnerable webmail viewer, no link or attachment required.
Greg breaks down the two distinct actors covered in Proofpoint's research: TA458, a mature, well-resourced group active across multiple webmail platforms (Zimbra, MDaemon, Roundcube, SOGo, and Horde) primarily targeting Ukraine, Eastern Europe, and militaries/ministries of foreign affairs; and TA488 (aka Void Blizzard, aka Laundry Bear), a comparatively scrappier contractor operation that leaned on a single Zimbra zero-day dubbed “ZimReaper” to steal credentials, full mailboxes, and up to 90 days of email history from Ukrainian government and U.S. targets.
The conversation covers how the half-click technique works under the hood (stored cross-site scripting via mishandled JavaScript event handlers in webmail HTML), how it differs from traditional phishing, the evidence pointing to a possible link between TA458 and GRU Unit 20728, why TA488's contractor status may explain its skittishness (burning down infrastructure after being outed) versus TA458's higher risk tolerance (including repeatedly firing exploits at targets that weren't even running vulnerable software), and what defenders running Zimbra, Roundcube, or similar platforms can actually do about it.
Resources Mentioned:
https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits
For more information about Proofpoint, check out our website.
Subscribe & Follow:
Stay ahead of emerging threats, and subscribe! Happy hunting!