THIS report details the activities of two Russian-aligned cyber espionage groups, TA488 and TA458, focusing on their exploitation of webmail servers for email and credential theft. Key findings include: 1) Both groups utilize sophisticated 'half-click' exploits in webmail clients, requiring victims to merely open an email. 2) TA488 operated undetected for five months, leveraging vulnerabilities in Zimbra, while TA458 adapts its SpyPress malware against multiple platforms, including Roundcube and SOGo.
3) Their targets predominantly include Ukrainian government bodies and US defense sectors. 4) Immediate recommendations include prompt patching of webmail applications, monitoring of outbound DNS queries, and auditing of app-specific passwords to enhance security.