TF-MAL-js.spypress
📛 Threat Title
Malware family: SpyPress
Description
ThreatFox malware family `js.spypress`. Printable name: SpyPress.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
js.spypress
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.spypress
IOC database
- Type
- domain
- Value
js.spypress- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-js.spypress
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.spypress
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
The execution of Operation RoundPress involves multiple variants of JavaScript payloads tailored to the webmail platform exploited. SpyPress .ROUNDCUBE, SpyPress .HORDE, SpyPress .MDAEMON, and SpyPress .ZIMBRA share a similar structure, aiming to capture credentials, steal email messages, and exfiltrate contacts.
-
web:blog.polyswarm.io
Operation RoundPress, a Russia-aligned cyberespionage campaign attributed to Fancy Bear, deploys SpyPress malware via cross-site scripting (XSS) vulnerabilities to steal sensitive email data from high-value webmail servers.
-
web:cyberpress.org
The campaign demonstrates advanced exploitation of cross-site scripting (XSS) vulnerabilities in widely used webmail servers-Roundcube, Horde, MDaemon, and Zimbra-to deploy custom JavaScript malware for intelligence gathering on high-value government and defense-related targets.
-
web:hivepro.com
When the recipient opens the email in a vulnerable webmail interface, the embedded JavaScript executes silently, launching the SpyPress malware . These payloads don't install anything persistently; instead, they live inside the email and activate only when viewed in an unpatched browser-based client.
-
web:malpedia.caad.fkie.fraunhofer.de
SpyPress Propose Change Actor (s): APT28 According to ESET, SpyPress is a set of Javascript payloads targeting different webmail frameworks (HORDE, MDAEMON, ROUNDCUBE, ZIMBRA). The observed payloads have common characteristics. All are similarly obfuscated, with variable and function names replaced with random-looking strings.
-
web:medium.com
In some cases, especially with Roundcube, SpyPress even creates Sieve rules that forward every incoming email to attacker-controlled accounts a chilling technique that persists even after the ...
-
web:rewterz.com
In some cases, the malware even created custom rules inside Roundcube (called Sieve rules), which secretly forwarded all incoming emails to the attacker's email address. The malicious JavaScript payload used in this operation is called SpyPress .
-
web:thehackernews.com
The malware , despite lacking a persistence mechanism, gets reloaded every time the booby-trapped email message is opened. "In addition, we detected a few SpyPress .ROUNDCUBE payloads that have the ability to create Sieve rules," ESET said.
-
web:undercodenews.com
Operation RoundPress uses four custom JavaScript payloads—SpyPress.HORDE, SpyPress .MDAEMON, SpyPress .ROUNDCUBE, and SpyPress .ZIMBRA—each crafted specifically for its target webmail platform. These payloads are heavily obfuscated, employing encrypted configurations and randomized code to slip past detection systems.
-
web:www.eset.com
Additionally, SpyPress .MDAEMON is able to set up a bypass for two-factor authentication. MONTREAL, BRATISLAVA — May 15, 2025 — ESET researchers have uncovered a Russia-aligned espionage operation, which ESET named RoundPress, targeting webmail servers via XSS vulnerabilities.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.