Suspected Chinese snoops caught breaking into universities' Roundcube mailservers
ID: 39e4aadf-a954-5846-b72d-ee53655fe6cc
STIX ID: report--39e4aadf-a954-5846-b72d-ee53655fe6cc
Feed Name: The Register (Security)
Proofpoint researchers observed an ongoing espionage campaign (tracked as UNK_MassTraction) targeting US and Canadian universities by exploiting a Roundcube XSS (CVE-2024-42009) to run a JavaScript loader that delivers the IceCube stealer, which harvests credentials and session tokens. The attackers then used a Roundcube deserialization vulnerability (CVE-2025-49113) to install SquareShell webshells and VShell implants; fallback loaders (SnowLight-related) and shared infrastructure point to China-aligned actors targeting physics, engineering, and national-security-related departments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
