Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities

Chinese Espionage Group Uses Roundcube Exploit Chain to Infiltrate Universities

A suspected Chinese espionage group has been using a sophisticated exploit chain to break into the networks of U.S. and Canadian universities, stealing sensitive data and establishing persistent access through webshells and backdoors. The attacks, which began in May, targeted physics and engineering departments, focusing on administrators and professors with national security links or those researching astrophysics and particle physics.

The group, tracked by Proofpoint as UNK_MassTraction, exploited a pair of critical vulnerabilities in the open-source email client Roundcube to gain access to university networks. The first exploit, CVE-2024-42009, allowed the attackers to execute JavaScript inside the victim’s browser, while the second, CVE-2025-49113, granted them a foothold in the mail server. This was achieved through a series of generic phishing emails that were designed to trick victims into opening them, allowing the initial exploit to take hold.

The scope of the attacks is not yet fully understood, but Proofpoint estimates that around a dozen universities may have been affected. Researchers believe that many more institutions may be impacted, with some possibly unaware of the breach. “There is a high likelihood that many victims have not been made aware of this activity yet,” said Greg Lesnewich, principal threat researcher at Proofpoint.

The use of email as an attack vector is particularly noteworthy, as it represents a departure from previous tactics used by Chinese state-sponsored espionage groups. Typically, these attackers would target edge devices such as routers and VPN concentrators to create a foothold into a network. Instead, the group behind UNK_MassTraction has opted for a more stealthy approach, using email to deliver an exploit chain that compromises the mail server rather than targeting individual users.

The targeting of universities with research links to national security or astrophysics and particle physics is also significant. This suggests that the attackers may be seeking sensitive information related to these fields, which could have strategic implications for China’s interests. However, the exact motivations behind the attacks remain unclear, and researchers have not been able to determine what specific data was stolen.

The incident serves as a reminder of the ongoing threat posed by state-sponsored espionage groups, particularly those aligned with China. As universities rely increasingly on digital technologies to facilitate research and collaboration, they must also prioritize cybersecurity measures to protect sensitive information from unauthorized access.

For institutions looking to mitigate similar threats, it is essential to stay vigilant and up-to-date with the latest security patches for email clients such as Roundcube. Regular security audits and monitoring can also help detect potential breaches before they escalate into major incidents. By taking proactive steps to secure their networks and data, universities can reduce the risk of falling victim to sophisticated attacks like UNK_MassTraction.


Source: CyberScoop — 2026-07-07