logo

Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities

ID: a4937d32-eb02-59e5-821c-9284ae34f42d

STIX ID: report--a4937d32-eb02-59e5-821c-9284ae34f42d

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-07-07

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

Proofpoint has observed a China-aligned cluster dubbed UNK_MassTraction exploiting critical, now-patched Roundcube flaws (CVE-2024-42009 XSS and CVE-2025-49113 post-auth RCE) to deliver a JavaScript infostealer named IceCube that harvests credentials, 2FA and cookies, then weaponizes a second vulnerability to install SquareShell or deploy VShell/SNOWLIGHT backdoors; targeted victims include physics and engineering departments at U.S. and Canadian universities, and the campaign uses reconnaissance, deferred triggers and anti-forensic techniques to maintain persistence and evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.