UNK_MassTraction Exploits Roundcube Flaws Against US, Canadian Universities
ID: bc8b4e82-305f-50b7-b2d0-5e3f0cf8e9a0
STIX ID: report--bc8b4e82-305f-50b7-b2d0-5e3f0cf8e9a0
Feed Name: HackRead
Proofpoint has uncovered an active, China-aligned espionage campaign (UNK_MassTraction) exploiting Roundcube vulnerabilities to compromise university mail servers—particularly physics and engineering departments tied to sensitive research. Attackers leverage CVE-2024-42009 (Roundcube XSS) to load a JavaScript loader called IceCube that harvests credentials and session data, then chain to CVE-2025-49113 (Crypt_GPG deserialization) to install SquareShell (a PHP web shell) and deploy VShell, an in-memory Go backdoor; operators also perform cleanup and persistence and reuse compromised accounts/domains. Proofpoint has provided IOCs (IPs, hashes, URLs) and recommends patching exposed Roundcube instances and reviewing logs and web directories.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
