CVE
CVE-2025-49113
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
Exploitation IoCs 5
Domain easysend[.]co
Filename InitTest.dll
Filename NppExport.dll
Filename RemoteLibUpdater.exe
Filename updater.rar
MITRE ATT&CK TTPs 4
Source Articles
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
A Russia-aligned threat cluster known as UAC-0099 is distributing a malicious Notepad++ plugin to deliver MATCHBOIL.V2 malware, a modified version of the C#-based loader MATCHBOIL. The attack begins with a phishing email containing an image that leads to a shortened URL, which redirects to a file-sharing service hosting a malicious ZIP file. The ZIP contains a VBScript that executes a decoy PDF while silently deploying a malicious DLL and additional payloads, including RemoteLibUpdater.exe (BURNYBEAR) and InitTest.dll. The campaign aims to establish persistence and conduct espionage, with no financial motive observed.
hacker-news Jul 24, 2026
Hackers exploit Roundcube flaw to spy on academic researchers
A China-linked threat cluster tracked as UNK_MassTraction has been exploiting vulnerabilities in Roundcube webmail servers at academic institutions in the U.S. and Canada since May 2026. The attackers target physics and engineering departments, deploying malware to steal credentials and establish persistent access. Exploitation involves CVE-2024-42009 and CVE-2025-49113 to deploy backdoors such as IceCube, SquareShell, and VShell. Proofpoint attributes the activity to a likely China-aligned espionage group based on infrastructure overlap and linguistic artifacts, though confidence is moderate.
bleeping-computer Jul 8, 2026