logo

UNK_MassTraction Exploits Roundcube Flaws Against US, Canadian Universities

ID: bc8b4e82-305f-50b7-b2d0-5e3f0cf8e9a0

STIX ID: report--bc8b4e82-305f-50b7-b2d0-5e3f0cf8e9a0

Feed Name: HackRead

Threat Score
88/100

Date Published: 2026-07-08

Date Updated: 2026-07-17

Author: Waqas

...
...

Proofpoint has uncovered an active, China-aligned espionage campaign (UNK_MassTraction) exploiting Roundcube vulnerabilities to compromise university mail servers—particularly physics and engineering departments tied to sensitive research. Attackers leverage CVE-2024-42009 (Roundcube XSS) to load a JavaScript loader called IceCube that harvests credentials and session data, then chain to CVE-2025-49113 (Crypt_GPG deserialization) to install SquareShell (a PHP web shell) and deploy VShell, an in-memory Go backdoor; operators also perform cleanup and persistence and reuse compromised accounts/domains. Proofpoint has provided IOCs (IPs, hashes, URLs) and recommends patching exposed Roundcube instances and reviewing logs and web directories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.