Roundcube turned official inboxes into a quiet entry point. The standard response is to look for stolen passwords or phishing clicks, but this campaign used mail-rendering flaws so a victim could be compromised just by opening a message. That makes the mailbox itself the attack surface, and it gives the operator access without the noise of credential theft.
Ukraine says the campaign has been tracked since 2023 and now spans three waves of attacks. Reuters reported more than 170 email accounts belonging to prosecutors and investigators were compromised, and Ukrainian officials say local government agencies were also targeted. The activity is attributed to APT28, the Russian state-linked group also known as Fancy Bear, BlueDelta, or Forest Blizzard.
The forward risk is persistence and abuse of trust. Once an official inbox is exposed, attackers can read sensitive correspondence, impersonate staff, and seed disinformation from accounts that already look legitimate.