CyberSecurityBoardThreat Intel · CVEs · Products
Attack Groups

Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities

July 7, 2026

A suspected China-aligned threat activity cluster tracked as UNK_MassTraction by Proofpoint has been exploiting critical Roundcube webmail vulnerabilities to target physics and engineering departments at U.S. and Canadian universities. The campaign, first detected in May 2026, exploits CVE-2024-42009 (CVSS 9.3) and CVE-2025-49113 (CVSS 9.9) to deploy a JavaScript credential stealer called IceCube, followed by the VShell post-exploitation tool or a web shell named SquareShell. The attackers use compromised senders and spoofed domains with lax DMARC policies to deliver phishing emails. IceCube harvests credentials, 2FA tokens, and cookies, then uses CSRF tokens to trigger remote code execution. If web shell deployment fails, a shell script delivers the SNOWLIGHT ELF loader, linked to the China-nexus cluster UNC5174. Proofpoint notes this is the first time Chinese hackers have been tied to Roundcube exploitation, previously associated with Russian state-sponsored groups. The campaign underscores the need to secure mail servers as thoroughly as other edge devices.

CVEs: CVE-2024-42009, CVE-2025-49113, CVE-2026-55200, CVE-2026-46817

Attack groups: UNK_MassTraction, UNC5174

Malware: IceCube, VShell, SquareShell, SNOWLIGHT

Companies: Proofpoint

Products: Roundcube