A suspected China-aligned threat activity cluster tracked as UNK_MassTraction by Proofpoint has been exploiting critical Roundcube webmail vulnerabilities to target physics and engineering departments at U.S. and Canadian universities. The campaign, first detected in May 2026, exploits CVE-2024-42009 (CVSS 9.3) and CVE-2025-49113 (CVSS 9.9) to deploy a JavaScript credential stealer called IceCube, followed by the VShell post-exploitation tool or a web shell named SquareShell. The attackers use compromised senders and spoofed domains with lax DMARC policies to deliver phishing emails. IceCube harvests credentials, 2FA tokens, and cookies, then uses CSRF tokens to trigger remote code execution. If web shell deployment fails, a shell script delivers the SNOWLIGHT ELF loader, linked to the China-nexus cluster UNC5174. Proofpoint notes this is the first time Chinese hackers have been tied to Roundcube exploitation, previously associated with Russian state-sponsored groups. The campaign underscores the need to secure mail servers as thoroughly as other edge devices.
CVEs: CVE-2024-42009, CVE-2025-49113, CVE-2026-55200, CVE-2026-46817
Attack groups: UNK_MassTraction, UNC5174
Malware: IceCube, VShell, SquareShell, SNOWLIGHT
Companies: Proofpoint
Products: Roundcube
Original source: thehackernews.com