securityonline.info 7/23/2026, 4:31:39 PM · external

TA488 and TA458 Steal Government Email Using Half-Click Webmail Exploits

TA488 and TA458 Steal Government Email Using Half-Click Webmail Exploits
CyberSIXT Evidence Panel
Primary Source proofpoint.com
Threat Actor
TA488

THIS report details the activities of two Russian-aligned cyber espionage groups, TA488 and TA458, focusing on their exploitation of webmail servers for email and credential theft. Key findings include: 1) Both groups utilize sophisticated 'half-click' exploits in webmail clients, requiring victims to merely open an email. 2) TA488 operated undetected for five months, leveraging vulnerabilities in Zimbra, while TA458 adapts its SpyPress malware against multiple platforms, including Roundcube and SOGo.

3) Their targets predominantly include Ukrainian government bodies and US defense sectors. 4) Immediate recommendations include prompt patching of webmail applications, monitoring of outbound DNS queries, and auditing of app-specific passwords to enhance security.

View Primary Source Via securityonline.info

Article by CyberSIXT