China-Aligned UNK_MassTraction Exploits Roundcube Servers to Target Universities
ID: 03182b0a-3310-5dbf-9696-6c5fb34f8b8e
STIX ID: report--03182b0a-3310-5dbf-9696-6c5fb34f8b8e
Feed Name: GBHackers
Proofpoint observed a China-aligned cluster dubbed UNK_MassTraction exploiting Roundcube XSS (CVE-2024-42009) to run an IceCube JavaScript stealer that harvests credentials and session data, then using a Crypt_GPG_Engine deserialization flaw (CVE-2025-49113) to deploy SquareShell webshells or an in-memory Go backdoor (VShell) on university mail servers; the report provides technical details, IOCs (IPs, URLs, SHA256), attribution indicators, and mitigation guidance including patching, DMARC enforcement, credential rotation, and searching for timestomped webshells.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
