Intentionally desktop-first — best experienced on a workstation
Portfolio
Threat Intelligence Analysis · Russia · Nation-State
Series · Part 2 of 2

After the Half-Click —
What Persistent Mailbox Access Makes Possible

Author
Yana Ivanov
Published
August 2026
Classification
Public — Educational
Threat Actors
TA458 (GRU) · TA488 · Lyceum
Attack Type
Post-Compromise · Persistence · C2
Severity
Critical — Post-Compromise
HOLLOWGRAPH disclosed July 20, 2026  ·  Calendar events dated 2050 as C2 dead drops  ·  60-day forecast included
Section 01

Executive Summary

Part 1 of this series documented the half-click exploit — the moment a Ukrainian government official opens a routine email in a vulnerable Zimbra client and, in the time it takes to read the first sentence, loses their credentials, their 2FA codes, and ninety days of email to Russian intelligence. That is where most analyses of Operation RoundPress stop.

This is the part that comes after.

The credential theft documented by Proofpoint, NSA, and FBI is not the end of the attack. It is the beginning of an access relationship. ZimReaper installs an app-specific password named "ZimbraWeb" — a credential that survives password resets, bypasses two-factor authentication, and provides persistent IMAP, POP3, and SMTP access to the victim's mailbox indefinitely. SpyPress goes further, installing a PHP webshell and six fallback persistence mechanisms directly on the mail server. The actor is not leaving. They are moving in.

What persistent mailbox access enables has received almost no public analysis. This report examines five post-compromise capabilities — silent MFA interception, timing attacks using stolen behavioral intelligence, calendar-based C2 infrastructure, hidden mailbox rule manipulation, and compromised-account lateral spread — and closes with a datestamped 60-day forecast of where this campaign goes next.

Persistence
Duration
ZimbraWeb app password survives password resets. Access continues until explicitly revoked.
12
HOLLOWGRAPH
Victims
Group-IB confirmed 12 infected systems using M365 calendars as C2. Active June 3 — July 9, 2026.
2050
Event Date
Used
HOLLOWGRAPH schedules C2 calendar events for May 13, 2050 to keep them out of the victim's view.
60
Day Forecast
Window
Datestamped predictions based on observed actor behavior patterns. Published August 1, 2026.
Section 02

What the Access Enables — Five Capabilities That Start After the Half-Click

The ZimbraWeb app password and the SpyPress PHP webshell are not the goal. They are the infrastructure for what comes next. Persistent mailbox access gives an attacker capabilities that go far beyond reading the victim's email — and most of them are not detectable by the victim, their organization, or standard security tooling.

1
Silent MFA Interception
Email-based multi-factor authentication — "Was this you? Click yes or no" — is widely deployed across government and enterprise systems as a second layer of account security. It assumes the email inbox is trustworthy. Once an attacker has persistent read and delete access to a compromised mailbox, that assumption collapses. The attacker reads the MFA confirmation email before the victim does, clicks approve, and deletes the notification from the inbox. On desktop email clients where MFA notifications arrive in the background, the victim may never see the push notification at all. The attack is timed to behavioral patterns learned from 90 days of stolen email — late at night, during a known meeting, while the victim is traveling. The ZimReaper exfiltration includes calendar data and email metadata that tells the attacker exactly when the victim is least likely to be watching their inbox.
CRITICAL
2
Calendar-Based C2 — The HOLLOWGRAPH Technique
On July 20, 2026, Group-IB disclosed HOLLOWGRAPH — a Windows backdoor attributed with high confidence to the Cavern framework, likely Iranian-nexus Lyceum, that uses a compromised Microsoft 365 mailbox's calendar as a two-way command-and-control dead drop. The malware authenticates to the Microsoft Graph API using valid credentials from the compromised account. Operator instructions arrive as encrypted calendar event attachments. Stolen files leave the same way. Every malicious event is scheduled for May 13, 2050 — a date far enough in the future that it never appears on the victim's actual calendar view. The secondary channel uses DNS tunneling via IPv6 AAAA queries to refresh credentials. The entire operation blends into legitimate Microsoft cloud traffic and leaves no obvious artifact for traditional network security tools. This technique is not uniquely Iranian. Any actor with persistent mailbox access — including TA458 and TA488 following a RoundPress compromise — can deploy calendar-based C2 against any mail platform that exposes a calendar API.
CRITICAL
3
Hidden Mailbox Rule Manipulation
Every major webmail platform — Zimbra, Roundcube, Microsoft 365, Gmail — allows users to create inbox rules that automatically filter, forward, delete, or redirect incoming email. An attacker with persistent mailbox access can create hidden rules that operate silently without the victim's knowledge. Documented uses include: silently forwarding all incoming email to an attacker-controlled address; auto-deleting security notifications before the victim sees them; redirecting financial communications to a secondary folder the attacker monitors; and suppressing MFA alerts, breach notifications, and IT security warnings. These rules survive password changes and, in some implementations, persist even through account recovery. Microsoft documented this technique in 2022 in the context of BEC attacks. In the RoundPress post-compromise context, the same capability is available to any actor that has established persistent mailbox access via ZimbraWeb or an equivalent mechanism.
CRITICAL
4
Lateral Spread via Trusted Sender
Both TA458 and TA488 used previously compromised legitimate sender accounts to deliver exploit emails to subsequent targets — documented in the Proofpoint Part 1 disclosure. With persistent mailbox access, this capability is available indefinitely, not just for the initial campaign wave. A compromised Ukrainian ministry official's mailbox becomes a persistent launch platform for delivering half-click exploit emails to the official's contacts — colleagues, counterparts in allied governments, contractors, international partners. The recipient has every reason to open an email from a known, trusted colleague. The exploit fires the moment they do. The trust network of each compromised account becomes the attack infrastructure for the next wave. This is the mechanism by which a targeted campaign against twelve individuals in June 2026 becomes a much broader intelligence collection operation by September.
HIGH
5
Outgoing Email Modification
Server-level access — which SpyPress establishes via PHP webshell — enables modification of outgoing email before it is signed by DKIM. An attacker operating from inside the compromised Zimbra server can insert tracking pixels into outgoing email signatures, replacing the legitimate logo with an externally-hosted image that beacons to attacker infrastructure when the email is opened by the recipient. Every time the compromised official sends an email, the attacker learns who read it, when, and from what IP address. This maps the victim's contact network in real time, identifies active communication partners, and provides geolocation intelligence on counterparts in other organizations. Unlike the initial compromise — which required delivering a malicious email to the victim — this capability requires no further action from either the victim or their contacts. The attacker is now passively collecting intelligence through every email the compromised official sends.
HIGH
Section 03

HOLLOWGRAPH — The Calendar as a Weapon

The HOLLOWGRAPH disclosure deserves its own section because it represents the clearest documented example of what post-compromise mailbox access enables at the infrastructure level. It was disclosed by Group-IB on July 20, 2026 — three days before the Proofpoint RoundPress advisory — and the two reports together describe a complete picture of how nation-state actors are using compromised email infrastructure as operational backbone, not just intelligence collection.

Attribution note: Group-IB attributes HOLLOWGRAPH with high confidence to the Cavern modular backdoor framework, citing matching command syntax and architecture. Researchers identified several technical similarities with the Iranian-nexus threat actor Lyceum. This is not a Russian actor — but the technique is platform-agnostic. Any actor with persistent mailbox access, including TA458 and TA488, can deploy calendar-based C2 using the same Microsoft Graph API mechanism. The technique, not the actor, is the finding.

Figure 1 — HOLLOWGRAPH Calendar C2 Operation
01
Initial Access — Compromised Microsoft 365 Account
The attacker obtains credentials for a Microsoft 365 account — either through phishing, credential stuffing, or purchase on criminal markets. This account, observed by Group-IB as linked to Israel, becomes the operational infrastructure for the campaign. HOLLOWGRAPH is deployed as a .NET NativeAOT-compiled DLL that masquerades as a Brotli compression library on disk, loaded by a separate orchestrator component on the victim host. The malware never contacts an attacker-owned server for any command or payload traffic.
02
C2 Channel Establishment — The Calendar Dead Drop
HOLLOWGRAPH authenticates to the Microsoft Graph API using valid credentials from the compromised M365 account. The malware supports exactly two commands: "get" for retrieving operator instructions, and "send" for exfiltrating stolen files. Instructions arrive as encrypted attachments to calendar events. Stolen files leave the same way. Every malicious event is dated May 13, 2050 — far enough in the future that it never appears on the mailbox owner's active calendar view. The entire operation looks like legitimate Microsoft cloud API traffic because it is authenticated against a real account using real credentials.
03
Credential Refresh — DNS Tunneling via IPv6
HOLLOWGRAPH maintains a secondary channel using DNS tunneling through IPv6 AAAA record queries against the attacker's domain cloudlanecdn[.]com. This channel is used to retrieve updated Microsoft Entra ID credentials — tenant ID, client ID, client secret, and target mailbox — which are saved locally in a file disguised as a log file. When the M365 credentials expire or are rotated, HOLLOWGRAPH refreshes them via DNS without any direct contact with attacker infrastructure. The use of IPv6 AAAA records adds an additional layer of obscurity — many organizations monitor IPv4 DNS traffic closely but have less visibility into IPv6 DNS queries.
04
Selective Engagement — Disciplined Operational Security
Group-IB identified 12 infected systems but observed only 3 actively communicating with the attacker during the observation window. The earliest communication was June 3, 2026; the most recent was July 9. The selective interaction pattern indicates deliberate operational discipline — the attacker is engaging only with intended targets at intended times, not running automated bulk collection. This mirrors the TA458 and TA488 behavioral pattern from Part 1: campaigns that are highly targeted rather than opportunistic, calibrated to the specific intelligence value of each victim.
Source: Group-IB Threat Intelligence, "HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels," July 20, 2026. MITRE ATT&CK: T1102.001 (Web Service: Dead Drop Resolver), T1048 (Exfiltration Over Alternative Protocol), T1071.004 (DNS)

The Zimbra parallel: HOLLOWGRAPH uses Microsoft 365 calendar APIs. Zimbra has a calendar API. Roundcube has calendar functionality. SOGo was originally designed as a groupware and calendar platform. Every webmail platform targeted by RoundPress has some equivalent of the calendar API that HOLLOWGRAPH exploits. The technique does not require Microsoft infrastructure — it requires persistent authenticated access to any mailbox with a calendar API. TA458 has that access in the organizations they have already compromised.

Section 04

What Can Be Detected — and Where the Gaps Are

The post-compromise capabilities described in Section 02 are harder to detect than the initial half-click exploit — because they use legitimate platform features, authenticated credentials, and normal API traffic. But they are not undetectable. The gap is not technical capability — it is operational configuration and awareness.

Capability Detection Method Tool Layer Availability
ZimbraWeb persistence Audit /opt/zimbra/log/audit.log for CreateAppSpecificPassword events named "ZimbraWeb" SIEM / Log Analysis Available now — requires log monitoring configuration
Silent MFA interception Monitor for MFA approvals that occur during unusual hours or when the user is known to be unavailable; correlate with email delete events in the same window UEBA / SIEM Requires behavioral baseline — not available in self-hosted Zimbra without additional tooling
Calendar C2 (HOLLOWGRAPH) Monitor Microsoft Graph API calls from non-interactive service accounts; alert on calendar events with attachment creation outside business hours or dated far in future SIEM / M365 Defender M365 Defender detects this natively — self-hosted Zimbra calendar API requires custom monitoring
Hidden mailbox rules Periodic audit of all inbox rules across accounts; alert on rules created by non-standard processes or outside business hours; specifically look for rules that forward, delete, or suppress security notifications SIEM / Exchange Admin Native in Exchange Online — requires manual audit process in self-hosted deployments
Outgoing email modification DKIM validation on outbound mail at the sending server; monitor for signature image URLs that don't match approved domain list; network monitoring for unusual outbound HTTP requests from mail server NDR / Mail Gateway Rarely configured — requires deliberate deployment
Lateral spread via trusted sender Email security platform at the delivery layer — detect exploit payload patterns in emails regardless of sender reputation; sender profile alone is insufficient when the account is legitimately compromised Email Security Detection rule targeting @import tag-splitting pattern submitted to Sublime Security's open-source rule feed (PR #4981, July 2026)
DNS tunneling (IPv6 AAAA) Monitor DNS query volume per host for IPv6 AAAA records; alert on high-frequency AAAA queries to low-reputation or newly registered domains; specifically flag base32/base64-encoded subdomains NDR / DNS Monitoring Requires DNS logging at the resolver level — often absent in smaller government IT environments

The structural problem remains: The organizations most targeted by these campaigns — self-hosted Zimbra and Roundcube deployments in Eastern European government agencies and defense contractors — are the least likely to have SIEM, UEBA, NDR, or any of the monitoring capabilities listed above. The detection methods exist. The operational capacity to deploy and monitor them does not, in most target organizations. This is not a solvable problem at the individual organization level without external support.

Section 05

60-Day Forecast — What the Pattern Suggests Next

The following predictions are analytical hypotheses based on observed actor behavior, platform targeting patterns, and post-disclosure timing. They are not confirmed intelligence. They are published here with a datestamp of August 1, 2026 — to be revisited in 60 days against what actually occurred.

Methodology note: These forecasts are based on three observed patterns: (1) TA458's documented behavior after previous public disclosures — burning infrastructure and rebuilding with new CVEs within 45-60 days; (2) the platform targeting progression from Roundcube to Zimbra to mDaemon to SOGo to Kerio, suggesting a systematic survey of self-hosted webmail platforms; and (3) the convergence of Russian and Iranian actors on the same post-compromise technique (calendar C2), which historically precedes broader adoption across threat actor communities. All predictions are the author's independent analytical assessment.

1
The July 23 NSA/FBI/Proofpoint joint disclosure burned the operation publicly. TA458's documented behavior after the ESET RoundPress disclosure in May 2025 was to pause, rebuild infrastructure, and return with new CVEs within approximately 60 days. Prediction: by late September 2026, new TA458 activity will be observed against a webmail platform not yet covered by the known CVE list — most likely Horde (which appeared in the 2026 target list but has received less public scrutiny) or a legacy enterprise webmail platform still widely deployed in Eastern Europe. The @import tag-splitting obfuscation technique is likely to evolve — expect a new obfuscation layer that bypasses the detection rules published in response to the July 2026 disclosure.
2
HOLLOWGRAPH demonstrates a technique — using a compromised mailbox calendar as a C2 dead drop — that is low-cost, highly evasive, and platform-agnostic. When one nation-state actor demonstrates a technique this effective, others adopt it. Prediction: within 60 days, a second threat actor will be observed using calendar-based C2 against a different target set. Russian GRU-adjacent actors, who already have persistent mailbox access in compromised Zimbra servers from the RoundPress campaigns, are the most likely candidates for early adoption — because they already have the access the technique requires.
3
The use of compromised legitimate sender accounts to deliver exploit emails — documented in the Proofpoint disclosure and in the HOLLOWGRAPH campaign — is likely to become the primary delivery mechanism for the next campaign wave. Cold-email delivery from attacker-controlled accounts is detectable. Delivery from a compromised Ukrainian ministry official's email to their NATO partners is not. Prediction: the next disclosed RoundPress-style campaign will show a measurably higher proportion of victim organizations that have existing trust relationships with previously compromised accounts — evidence that the lateral spread mechanism is being deliberately exploited rather than used as a backup delivery option.
4
Proofpoint noted in the July 23 advisory that LLMs will likely increase TA458's vulnerability discovery rate. This prediction extends that observation: the window between a new webmail CVE being patched and being actively exploited will compress from the current 30-90 day range to under 14 days within the next two campaign cycles. If accurate, organizations that could previously survive a 30-day patch cycle will face exploitation before they can respond. Prediction: at least one webmail CVE disclosed between August and October 2026 will show evidence of exploitation within 14 days of patch release.

Forecast published August 1, 2026. To be revisited against observed activity in October 2026.

Section 06

The Access Is the Asset

Part 1 of this series described the half-click — the moment the exploit fires and the credentials leave the building. Most threat intelligence analysis of Operation RoundPress stops there, because that is where the initial access ends and where the measurable, attributable activity becomes harder to trace.

But the credential theft is not the objective. It is the admission ticket. What TA458 and TA488 are building — one compromised Zimbra server at a time, one app-specific password at a time — is a persistent presence inside the communications infrastructure of the organizations most relevant to the current geopolitical conflict. Ukrainian ministries. NATO governments. Defense contractors. Nuclear facility operators. The access, once established, can be leveraged indefinitely: for intelligence collection, for MFA bypass, for lateral spread, for calendar-based C2, for the kind of persistent passive surveillance that does not require any further action from the attacker.

The HOLLOWGRAPH disclosure changes what we should be looking for. The question is no longer just "did the half-click exploit fire?" The question is "what did the actor do with the access after it did?" And the answer — calendar events dated 2050, DNS tunneling through IPv6, outgoing emails modified to carry tracking pixels, MFA notifications silently intercepted and deleted — is that the access enables an entire operational layer that is almost entirely invisible to standard security tooling.

The convergence of Russian and Iranian techniques around compromised mailbox infrastructure is the signal I find most significant. When two separate nation-state actor communities independently arrive at the same technique — using a legitimate cloud service as C2 infrastructure — it means the technique works well enough to be worth the operational security risk. Broader adoption across the threat actor community is the predictable next step.

The email remains the most reliable attack surface. The mailbox, once compromised, becomes something more: an operational platform, a surveillance tool, a launch pad for the next target. The patch gap documented in Part 1 is not going to close by itself. The post-compromise capabilities documented in Part 2 are already in use. The 60-day forecast above will either be validated or corrected by what happens next.

This analysis is based on publicly available information including Group-IB's HOLLOWGRAPH disclosure (July 20, 2026), Proofpoint's Operation RoundPress advisory (July 23, 2026), Microsoft's documentation of mailbox rule abuse (2022), and MITRE ATT&CK technique documentation. The 60-day forecast in Section 05 represents independent analytical hypothesis — not confirmed intelligence. The outgoing email modification capability described in Finding 5 represents a technically validated but not yet publicly documented post-compromise technique; it is analytical synthesis based on known capabilities of the SpyPress PHP webshell and standard SMTP relay architecture. This analysis is the author's independent work, produced as a contribution to the security community. Part 1 of this series is available at yanaivanov.com/analysis/roundpress_analysis.html.

YI
Yana Ivanov
Security Analyst  ·  Threat Intelligence  ·  Detection Engineering

I'm a security researcher in Connecticut. Analysis is the part I love: tracing threat actor behavior, pulling apart supply chain attacks, and following evidence even when it lands on "unknown." When a question needs a tool that doesn't exist, I build it; most of the tools on this site started that way. Before security I spent 15 years designing enterprise software, which is why my tools assume a human will actually have to use them. I contribute detection rules to Sublime Security's open-source production ruleset. Security+ in progress. Everything here is independent work, shared as a contribution to the security community.

Portfolio