bleeping-computer · Crawled Jul 8, 2026

Hackers exploit Roundcube flaw to spy on academic researchers

1 Malware 2 CVEs
Read original article ↗

AI Summary

A China-linked threat cluster tracked as UNK_MassTraction has been exploiting vulnerabilities in Roundcube webmail servers at academic institutions in the U.S. and Canada since May 2026. The attackers target physics and engineering departments, deploying malware to steal credentials and establish persistent access. Exploitation involves CVE-2024-42009 and CVE-2025-49113 to deploy backdoors such as IceCube, SquareShell, and VShell. Proofpoint attributes the activity to a likely China-aligned espionage group based on infrastructure overlap and linguistic artifacts, though confidence is moderate.

AI-extracted · verify before operational use

Extracted Entities 3 found

MITRE ATT&CK TTPs 8 techniques