logo

Hackers exploit Roundcube flaw to spy on academic researchers

ID: c48a1a49-dff7-5dee-adce-fe9ab4819b19

STIX ID: report--c48a1a49-dff7-5dee-adce-fe9ab4819b19

Feed Name: Bleeping Computer

Threat Score
82/100

Date Published: 2026-07-08

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

Proofpoint reports an active China-linked espionage campaign named UNK_MassTraction that exploits Roundcube vulnerabilities (CVE-2024-42009 and CVE-2025-49113) to deliver a credential stealer (IceCube), attempt installation of a PHP webshell (SquareShell), and deploy a Go-based backdoor (VShell), targeting physics, engineering, and national-security-related research at U.S. and Canadian universities; defenders are urged to apply patches and treat mail servers as high-risk remote-access points.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.