Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
ID: a4937d32-eb02-59e5-821c-9284ae34f42d
STIX ID: report--a4937d32-eb02-59e5-821c-9284ae34f42d
Feed Name: The Hacker News
Proofpoint has observed a China-aligned cluster dubbed UNK_MassTraction exploiting critical, now-patched Roundcube flaws (CVE-2024-42009 XSS and CVE-2025-49113 post-auth RCE) to deliver a JavaScript infostealer named IceCube that harvests credentials, 2FA and cookies, then weaponizes a second vulnerability to install SquareShell or deploy VShell/SNOWLIGHT backdoors; targeted victims include physics and engineering departments at U.S. and Canadian universities, and the campaign uses reconnaissance, deferred triggers and anti-forensic techniques to maintain persistence and evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
