s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-js.spypress

📛 Threat Title

Malware family: SpyPress

Category: SpyPress First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `js.spypress`. Printable name: SpyPress.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain js.spypress VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.spypress

IOC database

Type
domain
Value
js.spypress
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-js.spypress

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.spypress

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    The execution of Operation RoundPress involves multiple variants of JavaScript payloads tailored to the webmail platform exploited. SpyPress .ROUNDCUBE, SpyPress .HORDE, SpyPress .MDAEMON, and SpyPress .ZIMBRA share a similar structure, aiming to capture credentials, steal email messages, and exfiltrate contacts.

  • web:blog.polyswarm.io

    Operation RoundPress, a Russia-aligned cyberespionage campaign attributed to Fancy Bear, deploys SpyPress malware via cross-site scripting (XSS) vulnerabilities to steal sensitive email data from high-value webmail servers.

  • web:cyberpress.org

    The campaign demonstrates advanced exploitation of cross-site scripting (XSS) vulnerabilities in widely used webmail servers-Roundcube, Horde, MDaemon, and Zimbra-to deploy custom JavaScript malware for intelligence gathering on high-value government and defense-related targets.

  • web:hivepro.com

    When the recipient opens the email in a vulnerable webmail interface, the embedded JavaScript executes silently, launching the SpyPress malware . These payloads don't install anything persistently; instead, they live inside the email and activate only when viewed in an unpatched browser-based client.

  • web:malpedia.caad.fkie.fraunhofer.de

    SpyPress Propose Change Actor (s): APT28 According to ESET, SpyPress is a set of Javascript payloads targeting different webmail frameworks (HORDE, MDAEMON, ROUNDCUBE, ZIMBRA). The observed payloads have common characteristics. All are similarly obfuscated, with variable and function names replaced with random-looking strings.

  • web:medium.com

    In some cases, especially with Roundcube, SpyPress even creates Sieve rules that forward every incoming email to attacker-controlled accounts a chilling technique that persists even after the ...

  • web:rewterz.com

    In some cases, the malware even created custom rules inside Roundcube (called Sieve rules), which secretly forwarded all incoming emails to the attacker's email address. The malicious JavaScript payload used in this operation is called SpyPress .

  • web:thehackernews.com

    The malware , despite lacking a persistence mechanism, gets reloaded every time the booby-trapped email message is opened. "In addition, we detected a few SpyPress .ROUNDCUBE payloads that have the ability to create Sieve rules," ESET said.

  • web:undercodenews.com

    Operation RoundPress uses four custom JavaScript payloads—SpyPress.HORDE, SpyPress .MDAEMON, SpyPress .ROUNDCUBE, and SpyPress .ZIMBRA—each crafted specifically for its target webmail platform. These payloads are heavily obfuscated, employing encrypted configurations and randomized code to slip past detection systems.

  • web:www.eset.com

    Additionally, SpyPress .MDAEMON is able to set up a bypass for two-factor authentication. MONTREAL, BRATISLAVA — May 15, 2025 — ESET researchers have uncovered a Russia-aligned espionage operation, which ESET named RoundPress, targeting webmail servers via XSS vulnerabilities.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.