logo

Suspected Chinese snoops caught breaking into universities' Roundcube mailservers

ID: 39e4aadf-a954-5846-b72d-ee53655fe6cc

STIX ID: report--39e4aadf-a954-5846-b72d-ee53655fe6cc

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2026-07-08

Date Updated: 2026-07-23

...
...

Proofpoint researchers observed an ongoing espionage campaign (tracked as UNK_MassTraction) targeting US and Canadian universities by exploiting a Roundcube XSS (CVE-2024-42009) to run a JavaScript loader that delivers the IceCube stealer, which harvests credentials and session tokens. The attackers then used a Roundcube deserialization vulnerability (CVE-2025-49113) to install SquareShell webshells and VShell implants; fallback loaders (SnowLight-related) and shared infrastructure point to China-aligned actors targeting physics, engineering, and national-security-related departments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.