Hackers exploit Roundcube flaw to spy on academic researchers

A China-linked threat cluster has been exploiting a vulnerability in Roundcube webmail servers at universities across the United States and Canada, stealing credentials and deploying backdoor malware. The campaign, tracked by cybersecurity researchers at Proofpoint as “UNK_MassTraction,” has been active since May and targets physics, engineering, and national security-related research departments.

Researchers have identified a pattern of malicious emails sent from compromised accounts or spoofed domains to trigger the exploitation of a cross-site scripting flaw in Roundcube. When opened in a vulnerable webmail client, these emails execute JavaScript code that loads a payload called IceCube. This malware is designed to harvest sensitive information such as usernames, passwords, cookies, and two-factor authentication data.

The attackers use “helpers” to exploit another vulnerability in Roundcube, tracked as CVE-2025-49113, which allows them to install SquareShell, a PHP webshell with remote code execution capabilities. If successful, the attacker gains control over the mail server; otherwise, they download a shell script that loads VShell, a Go-based backdoor commonly used by Chinese threat actors.

The UNK_MassTraction campaign appears to have selected servers previously deemed vulnerable to CVE-2024-42009 and CVE-2025-49113, suggesting some reconnaissance was performed prior to the attacks. Proofpoint assesses that this campaign is likely linked to China-aligned espionage actors based on infrastructure overlaps with a covert VPS network associated with multiple Chinese threat groups.

Administrators of Roundcube systems are advised to apply the latest security updates addressing these vulnerabilities and treat mail servers with the same diligence as VPNs or other remote access nodes. The incident highlights the importance of staying up-to-date with security patches, conducting regular vulnerability assessments, and monitoring for suspicious activity on internet-facing systems.

This campaign also underscores the need for researchers and administrators to be vigilant in protecting sensitive information from cyber threats. As Proofpoint notes, attribution is just an assessment and not a high-confidence one, emphasizing the importance of proactive defense rather than relying solely on attribution.


Source: Bleeping Computer — 2026-07-08