logo

BlueDelta Exploits Ukrainian Government Roundcube Mail Servers to Support Espionage Activities

ID: 57dd43e2-d0b3-4ae7-850f-e678654ed99a

STIX ID: report--57dd43e2-d0b3-4ae7-850f-e678654ed99a

Threat Score

90/100

Uploaded: 2026-08-11

Published Date: 2023-06-19

Last Modified Date: 2023-06-19

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Recorded Future (Insikt Group) and CERT-UA report that the BlueDelta threat cluster (linked to APT28/GRU) ran a targeted spearphishing campaign against Ukrainian government entities, exploiting Roundcube vulnerabilities (CVE-2020-35730, CVE-2021-44026, CVE-2020-12641) and overlapping with prior Outlook exploitation (CVE-2023-23397) to execute JavaScript payloads that install forwarding rules, exfiltrate session cookies, address books, and Roundcube database information; the report includes infrastructure pivots, domains/IP IoCs, ATT&CK mappings, and mitigation guidance.**