China-Linked Hackers Target University Researchers Through Roundcube Flaws

A China-linked threat cluster known as UNK_MassTraction targets Roundcube webmail servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware. The campaign, observed since May, focuses on physics and engineering departments, professors, administrators, and organizations involved in astrophysics, particle physics, or national security-related research.

The attack begins with malicious emails sent from compromised accounts or spoofed domains. Opening these emails in a vulnerable Roundcube client triggers a cross-site scripting flaw tracked as CVE-2024-42009, which executes JavaScript code that loads a payload called IceCube. This fully-featured stealer harvests usernames, passwords, cookies, two-factor authentication data, and browser information from victims.

Proofpoint assesses that UNK_MassTraction is likely a China-aligned espionage actor based on overlapping infrastructure with known Chinese threat groups and Chinese-language artifacts in earlier phishing emails. The attackers also exploit a deserialization flaw, CVE-2025-49113, to install the SquareShell PHP webshell for remote code execution, or fall back to loading the VShell Go-based backdoor directly in memory. Proofpoint notes that attribution remains an assessment rather than a high-confidence conclusion.

Read More at the original source →