Suspected Chinese Threat Group Targets Universities via Vulnerable Roundcube Servers
ID: 1cc49b8c-6eb6-53d5-93e0-2a3624fbdd51
STIX ID: report--1cc49b8c-6eb6-53d5-93e0-2a3624fbdd51
Feed Name: Infosecurity Magazine (News)
Threat Score
Proofpoint tracked a China-aligned cluster, UNK_MassTraction, exploiting Roundcube vulnerabilities (CVE-2024-42009 XSS and CVE-2025-49113 deserialization) at U.S. and Canadian universities to steal credentials via an IceCube JavaScript payload and to deploy webshells and the VShell in-memory backdoor for follow-on access; the activity targeted physics and engineering departments and is assessed as espionage-focused.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
