A China-Linked Threat Cluster is Stealing Credentials from Academic Researchers through Roundcube Servers
A sophisticated hacking campaign has been uncovered, targeting vulnerable servers at universities in the United States and Canada. The attackers, linked to a China-based threat cluster, have been exploiting two previously identified vulnerabilities in Roundcube email clients to gain access to sensitive information and deploy malware on compromised machines.
The campaign, dubbed “UNK_MassTraction” by cybersecurity researchers at Proofpoint, has been observed since May and appears to be focusing on specific departments, including physics, engineering, and research organizations involved in astrophysics, particle physics, or national security. The attackers are specifically targeting administrators, professors, and other personnel with access to sensitive information.
The attacks begin with a phishing email sent from compromised accounts or spoofed domains, using generic lures designed to entice victims into opening the message in their vulnerable Roundcube webmail client. Once opened, the email triggers the exploitation of a cross-site scripting flaw, tracked as CVE-2024-42009, which executes JavaScript code inside the victim’s browser and loads a malicious payload called IceCube.
IceCube is described by researchers as a “fully-featured Roundcube stealer,” capable of harvesting usernames, passwords, cookies, two-factor authentication data, and browser information. The malware uses additional techniques to exploit another Roundcube deserialization flaw, tracked as CVE-2025-49113, in an attempt to gain remote code execution on the mail server.
If successful, the attacker gains access to sensitive systems; otherwise, the malware downloads a shell script that loads another payload, VShell, directly into memory. VShell is a commodity backdoor commonly used by Chinese threat actors and provides interactive shell access and port forwarding capabilities.
Researchers believe UNK_MassTraction may be a China-aligned espionage actor due to several factors, including overlapping infrastructure with known covert networks associated with multiple China-linked threats and the presence of Chinese-language artifacts in earlier phishing emails. However, Proofpoint emphasizes that attribution is an assessment rather than a high-confidence conclusion.
What’s most concerning about this campaign is the apparent reconnaissance performed by the attackers prior to launching the attacks. They appear to have identified servers previously deemed vulnerable to CVE-2024-42009 and CVE-2025-49113, indicating a level of sophistication and planning involved in these operations.
To mitigate these types of attacks, administrators of Roundcube systems are advised to apply the latest security updates that address the two identified flaws. It’s also essential for organizations to treat mail servers with similar diligence as they would VPNs or other remote access nodes – after all, a compromised email client can be a gateway to sensitive systems.
As Proofpoint notes, it’s crucial for security teams to test every layer of their environment before attackers do. By simulating breach and attack scenarios, organizations can identify vulnerabilities and strengthen their defenses against sophisticated threats like UNK_MassTraction.
Source: Bleeping Computer — 2026-07-08