logo

China-Aligned UNK_MassTraction Exploits Roundcube Servers to Target Universities

ID: 03182b0a-3310-5dbf-9696-6c5fb34f8b8e

STIX ID: report--03182b0a-3310-5dbf-9696-6c5fb34f8b8e

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-07-08

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

Proofpoint observed a China-aligned cluster dubbed UNK_MassTraction exploiting Roundcube XSS (CVE-2024-42009) to run an IceCube JavaScript stealer that harvests credentials and session data, then using a Crypt_GPG_Engine deserialization flaw (CVE-2025-49113) to deploy SquareShell webshells or an in-memory Go backdoor (VShell) on university mail servers; the report provides technical details, IOCs (IPs, URLs, SHA256), attribution indicators, and mitigation guidance including patching, DMARC enforcement, credential rotation, and searching for timestomped webshells.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.