logo

Suspected Chinese Threat Group Targets Universities via Vulnerable Roundcube Servers

ID: 1cc49b8c-6eb6-53d5-93e0-2a3624fbdd51

STIX ID: report--1cc49b8c-6eb6-53d5-93e0-2a3624fbdd51

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-07-07

Date Updated: 2026-07-19

...
...

Proofpoint tracked a China-aligned cluster, UNK_MassTraction, exploiting Roundcube vulnerabilities (CVE-2024-42009 XSS and CVE-2025-49113 deserialization) at U.S. and Canadian universities to steal credentials via an IceCube JavaScript payload and to deploy webshells and the VShell in-memory backdoor for follow-on access; the activity targeted physics and engineering departments and is assessed as espionage-focused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.