# A consolidated analysis of five Russian actor clusters across a fake Notepad++ plugin chain, cloud-service dead drops

## Summary

Six publications from CERT-UA, ESET, Unit 42, Proofpoint and StrikeReady, spanning 2023 to July 2026, describe five separate Russian actor clusters. Read together, they reveal a shared pattern clear enough to call an operating doctrine: **exploit nothing at all, or exploit precisely the thing nobody treats as an attack surface.**

UAC-0099 delivers malware through the entirely legitimate plugin-loading mechanism of Notepad++ — CERT-UA states plainly that no vulnerability was exploited, neither in the software nor in its supply chain. Gamaredon has moved its primary exfiltration channel to commercial cloud storage services, and uses paste, blogging and social media platforms as dead drop resolvers. APT28 and Laundry Bear exploit XSS in webmail — a vulnerability class treated as second-tier next to RCE for two decades.

The second thread matters more for readers outside Ukraine. The US government writes plainly in its July 2026 joint advisory that extensive targeting of Ukrainian users, ahead of use against the US and other NATO allies, reflects an increasing trend: Ukraine is both a priority target and a **test bench for malicious cyber techniques before broader global deployment**.

**Priority action: if your organisation runs Zimbra Collaboration Suite, check the version now — and after patching, review** `audit.log` **for an app-specific password named** `ZimbraWeb`**. The patch does not revoke what was already taken.**

* * *

## Actor Map and Naming Convention

Naming across this source set is heavily fragmented. For readability, the table below is the cross-reference; from that point on this article uses **one bolded name** consistently.

| Name used here | Other names | Attribution | Attribution source |
| --- | --- | --- | --- |
| **UAC-0099** | — | Russia-aligned, active since at least mid-2022 | CERT-UA |
| **Gamaredon** | Armageddon, Primitive Bear | 18th Center of Information Security, FSB; believed to operate from occupied Crimea | Security Service of Ukraine (SSU) |
| **Turla** | Snake | Center 16, FSB | NCSC (UK) |
| **APT28** | Sednit, Fancy Bear, BlueDelta, Fighting Ursa, Forest Blizzard, Sofacy, Pawn Storm, TA422, ITG05 | Russian military intelligence | Multiple; ESET attributes Operation RoundPress at **medium confidence** |
| **Laundry Bear** | Void Blizzard, CL-STA-1114, TA488, UNK\_PitStop | Russian state-supported | Dutch intelligence (AIVD/MIVD); Microsoft; NSA/CISA joint advisory |
| **UNK\_HeatSink** | — | Russia-linked | Proofpoint (validated name for the actor StrikeReady identified) |
| **TA458** | — | Likely a Russian military intelligence operation, **no overlap with APT28** | Proofpoint |

> **Worth flagging:** vendors do not agree on where to merge and where to split. Proofpoint says it could not tie TA488 to Void Blizzard from its own telemetry, and that US government partners confirmed the association. Seqrite attributed its January 2026 case to APT28 at medium confidence, while Dutch intelligence treats Laundry Bear and APT28 as **separate actors**. The joint advisory itself cautions the name mapping may not be one-to-one. When citing onward, keep each vendor's own name rather than collapsing them.

## Consolidated Timeline

| Date | Event |
| --- | --- |
| 2023 | Operation RoundPress begins (**APT28**), targeting Roundcube, Horde, Zimbra |
| June 2023 | Recorded Future documents **APT28** abusing multiple Roundcube flaws |
| Nov 2024 | CVE-2024-11182 (MDaemon) patched in 24.5.1 — previously used as a zero-day |
| Early 2025 | ESET observes **Gamaredon** and **Turla** co-compromising machines in Ukraine |
| May 2025 | ESET publishes Operation RoundPress; AIVD/MIVD and Microsoft disclose Laundry Bear / Void Blizzard |
| July 2025 | **Laundry Bear** begins exploiting CVE-2025-66376 (Zimbra) as a zero-day |
| Sept 2025 | StrikeReady discloses the `.ICS` zero-day attack, CVE-2025-27915 (**UNK\_HeatSink**) |
| 6 Nov 2025 | Zimbra patches CVE-2025-66376 in 10.0.18 / 10.1.13 |
| 31 Dec 2025 | Zimbra 10.0 reaches end of life |
| Jan 2026 | Seqrite analyses a case at a Ukrainian state hydrology agency (Operation GhostMail) |
| Feb 2026 | Proofpoint loses sight of **Laundry Bear** activity |
| Mar 2026 | CISA adds CVE-2025-66376 to KEV (18 Mar); **TA458** exploits Kerio and SOGo zero-days (CVE-2026-8496) |
| 25 Jun 2026 | ESET publishes its **Gamaredon** 2025 report |
| 21 Jul 2026 | CERT-UA discloses the **UAC-0099** fake Notepad++ plugin campaign |
| 23 Jul 2026 | NSA, CISA and 15 governments publish joint advisory AA26-204A on Zimbra |

* * *

# Branch A — Abusing Legitimate Software on the Endpoint

## UAC-0099: The Notepad++ Chain

![Notepad++ malicious plugin](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5ULiK2c7eL5isjO3O6NWXaCFL4sc8Znxd0LnivmJIcRXay0i8YzapqwH6odHGGrL0H0dj6lPuDzhDGBkwUR6XE2RIoMk2ukPzOIDfUBn84oI10M5Sx4sZsmmIx29NcAA0SsUfDNAuVHDP2lFoz7bKw48wk2onJH9-4udbqS8Giuyvh36pWFAMmmrA1Wyj/s1600/notepad.png align="center")

*Components in the campaign's delivery package (source: The Hacker News / CERT-UA).*

From mid-summer 2026, CERT-UA observed **UAC-0099** changing its TTPs. The new chain runs as follows:

1.  A phishing email carries an image attachment; clicking it opens a URL concealed behind a link shortener.
    
2.  The request forwards to a file-sharing service such as `EasySend[.]co` to retrieve a ZIP archive.
    
3.  The ZIP contains a VBScript masquerading as a PDF document via a double file extension (`.pdf.vbs`).
    
4.  On execution, a decoy PDF is downloaded and displayed to the victim as a distraction, while the script silently downloads a second archive named `Evernote.zip`.
    
5.  `Evernote.zip` contains: **a complete copy of the legitimate Notepad++ 8.8.3**, a malicious DLL plugin (`NppExport.dll`), a password-protected archive (`updater.rar`), and the legitimate WinRAR executable (`winrar.exe`).
    
6.  The VBScript extracts the package into a randomly named directory and launches Notepad++, which **loads** `NppExport.dll` **through its own standard plugin mechanism**.
    
7.  That DLL is LUNCHPOKE. It creates `%PUBLIC%\Libraries\fFthY3-Ytrevc3w-ab3\` (the name varies between runs) and extracts `updater.rar` using a password, yielding `RemoteLibUpdater.exe` and `InitTest.dll`.
    
8.  LUNCHPOKE **copies the system utility** `schtasks.exe` **to** `%PUBLIC%\Wallpapers\Background.exe`, then uses that copy to create a scheduled task named `\W1n3r-U09oTy-Ap5\Updates`, running `RemoteLibUpdater.exe` with the arguments `setup nodisplay` **every three minutes**.
    
9.  `RemoteLibUpdater.exe` is BURNYBEAR, a loader for `InitTest.dll`.
    
10.  `InitTest.dll` is MATCHBOIL.V2 — a modified version of MATCHBOIL, a C#-based loader capable of fetching and running follow-on payloads. It collects a system fingerprint via WMI (CPU ID, BIOS serial, MAC) and beacons to `geostat[.]lat`. **Three details worth separating out.** Each has value beyond this campaign:
     

*First, no vulnerability at all.* CERT-UA and BleepingComputer both stress the point: this is not a new flaw in Notepad++, nor a compromise of the software's supply chain infrastructure. The attackers simply rely on Notepad++ automatically loading plugin files placed in its directory — documented, ordinary behaviour. Every legitimate file in the package is genuinely signed. There is no hash to block.

*Second, copying* `schtasks.exe` *under a new name.* This is LOLBIN masquerading in its simplest effective form: detection rules keyed on the process name `schtasks.exe` creating a task will not fire, because the process creating this task is named `Background.exe` and lives in `%PUBLIC%\Wallpapers\`. Only rules keyed on path or original hash will catch it.

*Third, the resource-exhaustion logic.* CERT-UA notes that if `RemoteLibUpdater.exe` is launched incorrectly — specifically, without arguments — BURNYBEAR instead activates logic designed to **exhaust the computer's RAM and processor**. This is not sandbox evasion; it is sandbox destruction. An analyst or automated system that runs the binary without knowing the correct arguments gets a hung machine rather than a working sample.

The three-minute task interval is also telling. It trades stealth for resilience: kill the process and the malware returns within three minutes. In a monitored environment that cadence is a signal; in an unmonitored one, it is insurance.

## Gamaredon 2025: Legitimate Services as Infrastructure

ESET's [Gamaredon 2025 report](https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/) (published 25 June 2026) describes a parallel path built on the same philosophy.

Throughout 2025, **Gamaredon** exclusively targeted governmental and military institutions in Ukraine. Its operators developed and deployed six new malicious PowerShell tools. Two infrastructure changes stand out:

*   File stealers were upgraded to support exfiltration to **commercial cloud storage services** — Wasabi, Tebi and Intercolo — which became the primary exfiltration method.
    
*   ESET documented abuse of multiple legitimate messaging, social media, blogging and paste services as **dead drops** for resolving C&C servers and distributing payloads. For defenders the implication is direct: outbound traffic no longer points at attacker infrastructure. It points at services the organisation may legitimately use, or at minimum has no clear reason to block. Domain reputation blocking is close to useless here.
    

## Division of Labour: The Target Handoff Model

The most notable development of 2025 is not tooling but **how these groups divide work between them**. ESET documented two separate handoff patterns.

**Gamaredon → Turla.** ESET uncovered the first known cases of collaboration between the two. In February 2025, **Gamaredon**'s PteroGraphin tool was used to restart **Turla**'s Kazuar v3 backdoor on a machine in Ukraine — most likely a recovery mechanism after the backdoor crashed or failed to launch automatically. In April and June 2025, Kazuar v2 was deployed using the PteroOdd and PteroPaste tools. The numbers describe the relationship: over that year ESET detected **Turla** on seven machines in Ukraine, while **Gamaredon** compromised hundreds if not thousands. **Turla** is interested only in machines holding highly sensitive intelligence, and **Gamaredon** provides the initial access. Both sit inside the FSB, but in different centres — Center 18 and Center 16.

**UAC-0099 → Sandworm.** In the same 2025 report, ESET documented a second example of cooperation and task sharing: **UAC-0099** conducting initial access operations, then transferring validated targets to Sandworm.

This is a clear division of labour: the volume group handles access and triage; the elite group takes handoff of the machines worth having. The practical consequence for defenders is that **a "commodity malware" alert on a high-value asset should not be closed at that severity**. It may be step one of a chain whose step two is executed by an entirely different group, with entirely different tooling, weeks later.

* * *

# Branch B — Webmail and XSS

## Operation RoundPress: XSS as a Long-Term Programme

![Operation RoundPress](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4HcCGpXvcTa_FgOS24O7oo53zcgUtQTglOouskOqnfwVEj3MezxJ_7_mC3tkosFCFobfz-f0qdL99AfIEBf57WE2oarfxJvTA6i1RM6_2UtSojRXFtFoz4vSjJl-Scmd6Ruk6ogsG83uPfnM70Spj8netZTFP84CFzoG6fffe7dWdoTRcuFEazAhh-2pN/s1600/figure-2.png align="center")

*Operation RoundPress campaign overview (source: ESET via The Hacker News).*

ESET published Operation RoundPress in May 2025, attributing it to **APT28** at medium confidence based on overlaps in the email addresses used to send spearphishing and similarities in how certain servers were configured. The campaign began in 2023.

The goal is stealing confidential data from specific email accounts. Most victims are governmental entities and defense companies in Eastern Europe — particularly Ukrainian government entities and defense firms in Bulgaria and Romania, some producing Soviet-era weapons destined for Ukraine. Additional targets include government, military and academic organisations in Greece, Cameroon, Ecuador, Serbia and Cyprus.

Four platforms, four different vulnerability states:

| Platform | Vulnerability | Status when exploited |
| --- | --- | --- |
| Horde | Old flaw, fixed in Horde Webmail 1.0 (2007) | Long patched |
| Roundcube | CVE-2023-43770 | Patched; added to CISA KEV Feb 2024 |
| Zimbra | CVE-2024-27443 | Patched |
| MDaemon | **CVE-2024-11182** (CVSS 5.3) | **Zero-day**; patched in 24.5.1, Nov 2024 |

The mechanism is simple: the code that triggers the XSS flaw sits inside the HTML of the email body and is **not visible to the user**. The email content itself is innocuous. The only requirement is that the target opens the message in a vulnerable webmail portal, assuming it clears the spam filter.

The payload is SpyPress — obfuscated JavaScript that steals webmail credentials and harvests messages and contact information. It has **no persistence mechanism**, but reloads every time the booby-trapped message is opened. Select variants also capture login history and 2FA codes, and **create an application password for MDaemon** to retain mailbox access even if the password or 2FA code is changed.

The sharpest detail is in the Roundcube variant: SpyPress.ROUNDCUBE creates a **Sieve rule** that sends a copy of every incoming email to an attacker-controlled address. Sieve rules are a native Roundcube feature, so the rule **keeps executing even when the malicious script is no longer running**. This is persistence with no malware involved — just a legitimate configuration of the application itself.

## The `.ICS` Zero-Day: When the Payload Is in a Calendar File

In September 2025, StrikeReady Labs disclosed a case from earlier that year: an apparent sender from `193.29.58.37` spoofed the Libyan Navy's Office of Protocol to send Brazil's military a then-zero-day exploit in Zimbra Collaboration Suite — **CVE-2025-27915** — via a malicious `.ICS` file, the popular calendar format.

![Spearphish email](https://strikeready.com/_next/image/?url=%2Fuploads%2F0day_1_a04d4e2698.png&w=1200&q=75 align="center")

*The spearphishing email spoofing the Libyan Navy's Office of Protocol (source: StrikeReady Labs).*

How StrikeReady found it is worth writing down for any TI team: **watch for ICS files larger than 10KB that contain JavaScript.** By their assessment this is rare enough that you can put an eyeball on every single one. This is hunting built on "what should not exist" rather than "what is known bad" — cheap, low noise, and entirely feasible for any organisation with an email gateway.

![ICS containing JavaScript](https://strikeready.com/_next/image/?url=%2Fuploads%2F0day_2_3a6156e3a5.png&w=1200&q=75 align="center")

*The ICS file containing obvious JavaScript (source: StrikeReady Labs).*

The payload is a comprehensive Zimbra Webmail data stealer:

*   60-second delay before code execution
    
*   Runs only if **more than three days** have passed since the last execution
    
*   Hides UI elements such as `InvHeaderTable` to reduce visual clues
    
*   **Monitors user activity**: if the user is inactive, it logs them out and then steals data
    
*   Creates hidden input fields to capture usernames and passwords at login
    
*   Searches all mail folders via Zimbra's own SOAP API and sends contents to the attacker, **repeating every four hours**
    
*   Steals scratch codes, trusted devices and app-specific passwords
    
*   Steals contacts, distribution lists and shared folders
    
*   Creates an email filter rule named **"Correo"** forwarding all mail to `spam_to_junk@proton.me`
    
*   Exfiltrates via HTTP POST with mode `no-cors` to `https://ffrk.net/apache2_config_default_51_2_1` The OPSEC detail StrikeReady spotted is a nice one: "Correo" is Spanish for mail. But Brazil speaks Portuguese, where the word would traditionally be "Correio." A small localisation slip, and exactly the kind of trace linguistic analysis tends to catch.
    

The logout-on-inactivity behaviour is also notable: it ensures the theft runs when nobody is watching the screen, while giving the terminated session a plausible explanation.

## Zimbra CVE-2025-66376: A Year of Reading Mailboxes

![Zimbra exploit emails](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWeIeXUk-7MFmxSMRqTtDjYCTFqBq7dE9Jl-NzTqDiLIsMv-EAzJitSzZrUHKwZozxWbS2hpvJ5NZf2Aj96wuQrUqvdeGFnfAaeHrELZriIP449-5oYrCO1lf2iNez1v-mVvI9dPVCW3VCyeOLqQzmtzYkuOGle1GAjbiptqEmgECvda1Ly15MilLR5Mw/s1600/emails.png align="center")

*Exploit emails from the Zimbra campaign (source: The Hacker News).*

This is the largest campaign in the source set, and the one carrying a government advisory.

**The vulnerability.** CVE-2025-66376 is a stored XSS flaw in Zimbra's Classic UI. A crafted HTML email abuses CSS `@import` handling to execute JavaScript **inside an authenticated webmail session** — meaning the payload inherits the user's full access to the mailbox.

The sanitizer bypass, which Proofpoint calls **tag-splitting**, works like this: hide an `svg onload` tag inside a `display:none` div, then break the tag apart with fake `@import` directives and HTML comments. Zimbra's sanitizer does not recognise the fragments as executable markup. It strips the `@import` sequences, and **the characters left behind join into** `<svg onload=eval(atob(...))>`, which the browser runs.

Put differently: the sanitizing step is the step that assembles the payload.

**Severity disagreement — worth noting for patch prioritisation.** The two CVSS records disagree on whether viewing the message counts as user interaction: [NVD scores it 6.1](https://nvd.nist.gov/vuln/detail/CVE-2025-66376) and says it does; MITRE scores it 7.2 and says it does not. Unit 42 calls it zero-click. All three describe the same behaviour: the message runs when it renders, and nothing else has to happen. For operations, **the useful prioritisation marker is not the CVSS number but the CISA KEV date: 18 March 2026.**

**Affected versions and patching.** Zimbra Collaboration 10.0 before `10.0.18` and 10.1 before `10.1.13`. Zimbra fixed it on 6 November 2025. But Zimbra 10.0 reached end of life on 31 December 2025, making `10.0.18` an emergency floor rather than a destination. The newest 10.1 release is `10.1.20`, out 20 July 2026, fixing four more stored XSS flaws in the Classic Web Client.

**The ZimReaper payload.** The chain begins with a phishing email carrying either an HTML attachment or HTML embedded in the message body; Unit 42 observed lures styled as a digest of current news headlines, while Proofpoint noted messages sent from adversary-controlled Proton Mail accounts and from previously compromised addresses. Once running, ZimReaper:

*   Steals the CSRF token and the browser's autofilled password
    
*   Pulls 2FA scratch codes and Zimbra version details through the platform's own APIs
    
*   **Exfiltrates over DNS queries** to actor infrastructure — a channel very few organisations monitor
    
*   **Brute-forces the Global Address List**, querying every two-character combination until the whole organisational directory comes back
    
*   Posts 90 days of the victim's mail to C2 as a TGZ archive
    
*   Mints an app-specific password named `ZimbraWeb` via `CreateAppSpecificPasswordRequest` In the January 2026 case at a Ukrainian state hydrology agency analysed by Seqrite, the payload also flipped `zimbraPrefImapEnabled` to TRUE for a second, quieter foothold.
    

**The single most important detail in the campaign:** app-specific passwords grant IMAP, POP3 or SMTP access **without two-factor authentication**, and as Seqrite noted, they **survive password resets**. Proofpoint observed **Laundry Bear** going on to send further exploit emails from compromised mailservers, and could not determine whether the app passwords or other stolen credentials were what got it back in.

**Victims and infrastructure.** Unit 42 counted at least nine C2 IP addresses and nine domains, each server live for an average of 35.4 days. The JavaScript payload changed little across the campaign. Targeting spans government, defense, transportation and financial organisations across NATO member states, Ukraine, CIS countries and Africa; US reporting adds government, scientific and defense industrial base entities, including nuclear installations.

The combination of a **stable payload with rapid infrastructure turnover** is characteristic of a well-resourced, disciplined group: they found a working formula in July 2025 and saw no need to retool.

**Is the campaign still live?** It depends whose telemetry you read. Unit 42 says threat actors continue to actively target unpatched ZCS instances, without saying whether this cluster is among them. Proofpoint says it has not observed activity from **Laundry Bear** since February 2026, and ties that silence to Seqrite's disclosure and the actor tearing down its own infrastructure. The joint advisory assesses the group will very likely keep going after Zimbra and other Western email systems.

## The Campaign Is Still Expanding

Since ESET's original May 2025 exposure, webmail exploitation has expanded in scope to Kerio Webmail and SOGo Webmail alongside Zimbra, MDaemon and Roundcube. In March 2026, **TA458** exploited zero-days in Kerio and the SOGo platform ([CVE-2026-8496](https://nvd.nist.gov/vuln/detail/CVE-2026-8496), patched in 5.12.8). For Kerio, **no CVE was issued** because the webmail product was old and outdated.

Proofpoint reports that since at least July 2025, **TA458** began removing stealing components and swapping in interactive backdoor mechanisms in its Roundcube variant of SpyPress, to enable long-term access to the instance. SpyPress uses a second Roundcube exploit (CVE-2025-49113) abusing Roundcube's file upload handler to trigger unsafe PHP deserialization, leading to arbitrary code execution and multiple backdoor or persistence mechanisms.

That is a meaningful shift in operational objective: from **one-shot theft** to **standing access**.

* * *

## Indicators of Compromise

> Compiled from CERT-UA, Unit 42, StrikeReady Labs and Xcitium. Domains and IPs are defanged. Re-fang only in controlled environments.

**Laundry Bear / CL-STA-1114 — Zimbra C2 (source: Unit 42)**

```plaintext
# IP addresses
37.120.247[.]228
64.226.124[.]190
104.248.134[.]194
185.86.79[.]95
193.238.152[.]66
194.156.103[.]193
216.252.238[.]18
216.252.238[.]64
216.252.238[.]104
 
# Domains — note the naming convention mimicking legitimate Zimbra services
analyticemailmeter[.]com
emailanalytics[.]com[.]ua
istc-cloud[.]com
mailnalysis[.]com
synacorzimbra[.]nl
zimbra-metadata[.]com
zimbrastat[.]com
zimbrasoft[.]com[.]ua
zmailanalytics[.]com
```

**UNK\_HeatSink — the .ICS campaign (source: StrikeReady Labs)**

```plaintext
C2                     hxxps://ffrk[.]net/apache2_config_default_51_2_1
Sender IP              193.29.58[.]37
Email forwarding       spam_to_junk@proton[.]me
Filter rule name       Correo
Attachment hash        ea752b1651ad16bc6bf058c34d6ae795d0b4068c2f48fdd7858f3d4f7c516f37
```

**UAC-0099 — the Notepad++ chain (source: CERT-UA)**

```plaintext
# C2
geostat[.]lat
 
# Abused intermediary services
EasySend[.]co   (file-sharing service — check context before blocking)
 
# On-host paths
%PUBLIC%\Libraries\fFthY3-Ytrevc3w-ab3\             (directory name varies per run)
%PUBLIC%\Libraries\<random>\RemoteLibUpdater.exe    = BURNYBEAR
%PUBLIC%\Libraries\<random>\InitTest.dll            = MATCHBOIL.V2
%PUBLIC%\Wallpapers\Background.exe                  = copy of schtasks.exe
 
# Scheduled task
\W1n3r-U09oTy-Ap5\Updates
  -> runs RemoteLibUpdater.exe with arguments: setup nodisplay
  -> interval: every 3 minutes
 
# Filenames in the delivery package
Evernote.zip           second-stage archive
NppExport.dll          = LUNCHPOKE (fake plugin)
updater.rar            password-protected archive
winrar.exe             legitimate WinRAR
notepad++.exe          legitimate Notepad++ 8.8.3
<name>.pdf.vbs         double-extension VBScript posing as a PDF
```

**Zimbra — server-side artifacts to review (source: Proofpoint, Seqrite)**

```plaintext
# In /opt/zimbra/log/audit.log
CreateAppSpecificPassword           -> find and remove any credential named "ZimbraWeb"
GetScratchCodesRequest              -> should be close to absent in normal use
 
# In account configuration
zimbraPrefImapEnabled = TRUE        -> review accounts with no business need for IMAP
 
# In unopened message content
Fragmented @import sequences in the HTML body
  -> Proofpoint has published a YARA rule matching this pattern
 
# In DNS logs
Long, random subdomain lookups against the domains listed above
```

**Gamaredon — abused services (source: ESET)**

```plaintext
# Cloud storage used as the primary exfiltration channel
Wasabi
Tebi
Intercolo
 
# Dead drop resolvers
Legitimate messaging, social media, blogging and paste services
(ESET does not name specific platforms in the public summary)
```

**Related CVEs**

```plaintext
CVE-2025-66376   Zimbra Classic UI stored XSS
                 NVD 6.1 / MITRE 7.2 (disagreement over user interaction)
                 Affects: ZCS 10.0 < 10.0.18 and 10.1 < 10.1.13
                 Patched: 6 Nov 2025 | CISA KEV: 18 Mar 2026
                 Exploited as a 0-day from July 2025
 
CVE-2025-27915   Zimbra — exploited via .ICS file (0-day at time of attack)
 
CVE-2024-11182   MDaemon XSS, CVSS 5.3 — 0-day; patched in 24.5.1 (Nov 2024)
 
CVE-2024-27443   Zimbra XSS — already patched when exploited
 
CVE-2023-43770   Roundcube XSS — CISA KEV Feb 2024
 
CVE-2025-49113   Roundcube — PHP deserialization via file upload handler
 
CVE-2026-8496    SOGo Webmail 0-day — patched in 5.12.8
                 Kerio Webmail: no CVE issued (product out of support)
```

* * *

## MITRE ATT&CK Mapping

| Tactic | Technique ID | Technique Name | Observed |
| --- | --- | --- | --- |
| Resource Development | T1583.001 | Acquire Infrastructure: Domains | C2 domains mimicking Zimbra service names |
| Resource Development | T1585.002 | Establish Accounts: Email Accounts | Laundry Bear's Proton Mail accounts |
| Initial Access | T1566.001 | Phishing: Spearphishing Attachment | UAC-0099's ZIP/VBS; UNK\_HeatSink's `.ICS` |
| Initial Access | T1566.002 | Phishing: Spearphishing Link | Link shortener → EasySend |
| Initial Access | T1189 | Drive-by Compromise | XSS firing on message render |
| Execution | T1204.002 | User Execution: Malicious File | Running the VBScript posing as a PDF |
| Execution | T1059.005 | Command and Scripting Interpreter: Visual Basic | First-stage VBScript |
| Execution | T1059.007 | JavaScript | SpyPress, ZimReaper, the `.ICS` stealer |
| Execution | T1059.001 | PowerShell | Gamaredon's new toolset |
| Execution | T1203 | Exploitation for Client Execution | Webmail client XSS exploitation |
| Persistence | T1053.005 | Scheduled Task | `\W1n3r-U09oTy-Ap5\Updates`, 3-minute interval |
| Persistence | T1137 | Office Application Startup *(analogous)* | Notepad++ plugin loading — see note |
| Persistence | T1556.006 | Modify Authentication Process: Multi-Factor Authentication | `ZimbraWeb` app password bypassing 2FA |
| Persistence | T1098 | Account Manipulation | Enabling `zimbraPrefImapEnabled`; Sieve rule creation |
| Defense Evasion | T1036.005 | Masquerading: Match Legitimate Name or Location | `schtasks.exe` → `Background.exe`; `NppExport.dll` |
| Defense Evasion | T1036.007 | Double File Extension | `.pdf.vbs` |
| Defense Evasion | T1027 | Obfuscated Files or Information | Obfuscated JavaScript; tag-splitting |
| Defense Evasion | T1140 | Deobfuscate/Decode Files or Information | `eval(atob(...))` |
| Defense Evasion | T1497 | Virtualization/Sandbox Evasion | 60s delay; 3-day window; resource-exhaustion logic |
| Credential Access | T1539 | Steal Web Session Cookie | CSRF token |
| Credential Access | T1555.003 | Credentials from Web Browsers | Autofilled password |
| Credential Access | T1111 | Multi-Factor Authentication Interception | 2FA scratch codes, trusted devices |
| Credential Access | T1056.001 | Input Capture: Keylogging | Hidden input fields capturing credentials |
| Discovery | T1087.003 | Account Discovery: Email Account | Global Address List brute-forcing |
| Discovery | T1082 | System Information Discovery | MATCHBOIL.V2's WMI fingerprint |
| Collection | T1114.002 | Email Collection: Remote Email Collection | 90 days of mail as TGZ |
| Command and Control | T1102.001 | Web Service: Dead Drop Resolver | Gamaredon's paste/blog/messaging services |
| Command and Control | T1071.001 | Application Layer Protocol: Web Protocols | HTTP POST with `no-cors` |
| Exfiltration | T1048.003 | Exfiltration Over Unencrypted Non-C2 Protocol | DNS query exfiltration |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | Wasabi, Tebi, Intercolo |
| Exfiltration | T1114.003 | Email Forwarding Rule | Sieve rules; the "Correo" filter |
| Impact | T1499 | Endpoint Denial of Service | BURNYBEAR's RAM/CPU exhaustion logic |

* * *

## Assessment

If one sentence has to come out of these six publications, it is this: **detection built on "what is known bad" is losing ground against this actor set.**

Try listing what a signature-based system could block in **UAC-0099**'s Notepad++ chain. Notepad++ is genuine and validly signed. WinRAR is genuine. The plugin-loading mechanism is a documented feature. `schtasks.exe` is a Microsoft binary. The only malicious component is `NppExport.dll`, and it sits inside a password-protected archive until the last moment. There is no exploited vulnerability to block, and no single behaviour that is, in isolation, illegitimate.

The same logic applies to **Gamaredon**: when the exfiltration channel is Wasabi and the dead drop is a public paste service, reputation blocklists contribute nothing. And to **Laundry Bear**: when the payload runs inside the user's own authenticated session, every action it takes is a legitimate action by that account.

What is left is detection built on **"what is anomalous."** A process named `Background.exe` in `%PUBLIC%\Wallpapers\` creating a scheduled task is anomalous. A scheduled task running every three minutes is anomalous. An `.ICS` file over 10KB containing JavaScript is anomalous. A webmail account querying the Global Address List with every two-character combination is anomalous. None of these require knowing a malware name in advance.

**On XSS.** For two decades XSS has ranked below RCE on severity scales, and the CVSS numbers reflect it — CVE-2024-11182 scored 5.3, CVE-2025-66376 scored 6.1 per NVD. But the three campaigns here show that for webmail, **XSS is equivalent to RCE in consequence**. It runs in an authenticated session, and the target was the mailbox all along. You do not need to escape the browser when what you want is inside the browser. StrikeReady is right that these examples should end the habit of treating XSS as a second-tier bug.

**On patching.** This is where many organisations' IR process stops too early. The patch closes the hole, not the account. The `ZimbraWeb` app-specific password grants IMAP/POP3/SMTP access without 2FA and **survives a password reset**. SpyPress's Sieve rule keeps forwarding mail even when the script no longer runs. A `zimbraPrefImapEnabled` flag set to TRUE stays TRUE. Bumping the version number is step one, not the last step.

**On Ukraine as a proving ground.** This is the US government's own assessment, not speculation: extensive Ukrainian targeting ahead of use against the US and NATO allies indicates Ukraine serves both as a priority target and a test bench for techniques. For a TI team anywhere, the practical consequence is direct: **reading CERT-UA is not following regional news, it is previewing what will appear elsewhere in six to eighteen months.**

### Relevance for Vietnam

The webmail half is the more concerning one for the domestic environment, for a purely economic reason: **Zimbra and Roundcube are widely deployed across Vietnamese government agencies, universities and mid-sized enterprises** because of low licensing cost relative to commercial platforms. This is also precisely the population that patches slowly, rarely opens `audit.log`, and almost never has a process for reviewing app-specific passwords.

The realistic risk for these organisations is not being directly targeted by a Russian APT — unlikely for most. The risk is **the same vulnerability being reused by other actors once details are public**. CVE-2025-66376 has been in KEV since 18 March 2026, the tag-splitting technique is publicly described, and Unit 42 confirms attackers continue to target unpatched instances. The gap between "one state group with a zero-day" and "many groups with an n-day" is usually measured in months.

On the endpoint side, the Notepad++ chain matters because it hits the same software category as the UAT-11795 campaign we analysed last week: **tools engineers and developers install outside the asset management catalogue**. Notepad++, WinRAR, 7-Zip — absent from software inventory, version unmonitored by anyone, and now their plugin mechanisms are an entry path too. CERT-UA's recommendation is to update WinRAR, 7-Zip and Notepad++ to current versions; this does not stop the chain above, but it removes known flaws an attacker could use for the next step.

The cheapest detection point in the whole article, if you only get one: **scheduled tasks running at intervals under five minutes.** Very few legitimate administrative tasks need that cadence, and it sits at exactly the persistence chokepoint the UAC-0099 chain must pass through.

* * *

## Recommendations

*   **Zimbra — in this order:** upgrade 10.1 deployments to at least `10.1.13` (ideally `10.1.20`) and move 10.0 deployments to a supported 10.1 build; **then** work the accounts — reset passwords, invalidate active sessions, regenerate 2FA scratch codes for any mailbox that opened a matching message; **only then** hunt the logs.
    
*   **Remove what the patch does not:** find and delete app-specific passwords named `ZimbraWeb` in `audit.log`, review accounts with `zimbraPrefImapEnabled = TRUE` and no business need, and audit every user-created forwarding and Sieve rule across the mail estate.
    
*   **Block and monitor:** push Unit 42's nine IPs and nine domains to firewall and DNS; alert on unusually long random subdomain lookups and on SOAP calls to `GetScratchCodesRequest`.
    
*   **Endpoint:** hunt for scheduled tasks with intervals under five minutes; hunt for copies of `schtasks.exe` outside `System32`; standardise download sources and version management for developer and IT tooling (Notepad++, WinRAR, 7-Zip) as you would for enterprise software.
    
*   **Email gateway:** adopt StrikeReady's hunting hypothesis — alert on `.ICS` files over 10KB containing JavaScript; and run Proofpoint's YARA rule for the fragmented `@import` pattern against messages already delivered but never opened.
    
*   **Process:** do not close "commodity malware" alerts on high-value assets at low severity — the target-handoff model between Russian groups means step one and step two can be weeks apart and executed by two different actors.
    

* * *

## References

*   CERT-UA — [UAC-0099: LUNCHPOKE, BURNYBEAR, updated MATCHBOIL.V2 and the use of Notepad++ 8.8.3](https://cert.gov.ua/article/6318634) (21 July 2026)
    
*   The Hacker News — [Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks](https://thehackernews.com/2026/07/fake-notepad-plugin-delivers.html) (24 July 2026)
    
*   BleepingComputer — [Hackers abuse Notepad++ plugins to stealthily install malware](https://www.bleepingcomputer.com/news/security/hackers-abuse-notepad-plus-plus-plugins-to-stealthily-install-malware/)
    
*   SecurityAffairs — [UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin](https://securityaffairs.com/195923/cyber-warfare-2/uac-0099-is-now-hiding-malware-inside-a-fake-notepad-plugin-to-target-ukrainian-organizations.html)
    
*   ESET — [ESET Research investigates Russian-aligned Gamaredon group](https://www.eset.com/us/about/newsroom/research/eset-research-investigates-russian-aligned-gamaredon-group-2025/) (25 June 2026)
    
*   ESET WeLiveSecurity — [Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances](https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/)
    
*   ESET — [Russian FSB-linked Gamaredon and Turla team up to target high-profile Ukrainian entities](https://www.eset.com/us/about/newsroom/research/eset-research-gamaredon-and-turla-target-high-profile-ukrainian-entities/) (19 September 2025)
    
*   The Hacker News — [Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers](https://thehackernews.com/2025/05/russia-linked-apt28-exploited-mdaemon.html) (15 May 2025)
    
*   ESET WeLiveSecurity — [Operation RoundPress](https://www.welivesecurity.com/en/eset-research/operation-roundpress/)
    
*   StrikeReady Labs — [0day .ICS attack in the wild](https://strikeready.com/blog/0day-ics-attack-in-the-wild/) (30 September 2025)
    
*   The Hacker News — [Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes](https://thehackernews.com/2026/07/russian-espionage-group-exploited.html) (23 July 2026)
    
*   Palo Alto Unit 42 — [Russian Global Webmail Espionage](https://unit42.paloaltonetworks.com/russian-webmail-espionage/) (23 July 2026)
    
*   Proofpoint — [TA488 Targets Zimbra Mailservers with Half-Click Exploits](https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits)
    
*   Proofpoint — [TA458 RoundPress Exploits](https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits)
    
*   CISA — [Joint Advisory AA26-204A](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a) (23 July 2026)
    
*   NSA — [Alert on Zimbra Collaboration Suite](https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4553352/nsa-and-partners-alert-zimbra-collaboration-suite-users-of-a-russian-state-supp/)
    
*   Seqrite — [Operation GhostMail: Russian APT exploits Zimbra Webmail to Target Ukraine State Agency](https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/)
    
*   Zimbra — [Release 10.1.20](https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.20)
