BlueDelta Exploits Ukrainian Government Roundcube Mail Servers to Support Espionage Activities
ID: 57dd43e2-d0b3-4ae7-850f-e678654ed99a
STIX ID: report--57dd43e2-d0b3-4ae7-850f-e678654ed99a
Threat Score
90/100
Uploaded: 2026-08-11
Published Date: 2023-06-19
Last Modified Date: 2023-06-19
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Recorded Future (Insikt Group) and CERT-UA report that the BlueDelta threat cluster (linked to APT28/GRU) ran a targeted spearphishing campaign against Ukrainian government entities, exploiting Roundcube vulnerabilities (CVE-2020-35730, CVE-2021-44026, CVE-2020-12641) and overlapping with prior Outlook exploitation (CVE-2023-23397) to execute JavaScript payloads that install forwarding rules, exfiltrate session cookies, address books, and Roundcube database information; the report includes infrastructure pivots, domains/IP IoCs, ATT&CK mappings, and mitigation guidance.**
