Suspected Chinese snoops caught breaking into universities' Roundcube mailservers
ID: 7ae0a45c-f138-54d0-ba49-3aa5ae0d3c89
STIX ID: report--7ae0a45c-f138-54d0-ba49-3aa5ae0d3c89
Feed Name: Proofpoint Blog
Proofpoint observed an ongoing espionage campaign (UNK_MassTraction) targeting US and Canadian university Roundcube webmail instances by exploiting CVE-2024-42009 XSS to deliver an infostealer (IceCube), then chaining to a deserialization exploit (CVE-2025-49113) to deploy SquareShell and VShell webshells; the actor used phishing lures, fallback SnowLight loaders, and infrastructure consistent with China-aligned operations, with fewer than 10 confirmed victims and an estimated few dozen targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
