logo

Suspected Chinese snoops caught breaking into universities' Roundcube mailservers

ID: 7ae0a45c-f138-54d0-ba49-3aa5ae0d3c89

STIX ID: report--7ae0a45c-f138-54d0-ba49-3aa5ae0d3c89

Feed Name: Proofpoint Blog

Threat Score
85/100

Date Published: 2026-07-08

Date Updated: 2026-07-17

...
...

Proofpoint observed an ongoing espionage campaign (UNK_MassTraction) targeting US and Canadian university Roundcube webmail instances by exploiting CVE-2024-42009 XSS to deliver an infostealer (IceCube), then chaining to a deserialization exploit (CVE-2025-49113) to deploy SquareShell and VShell webshells; the actor used phishing lures, fallback SnowLight loaders, and infrastructure consistent with China-aligned operations, with fewer than 10 confirmed victims and an estimated few dozen targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.