bleeping-computer · Crawled Jul 8, 2026
Hackers exploit Roundcube flaw to spy on academic researchers
1 Malware 2 CVEs
Read original article ↗
AI Summary
A China-linked threat cluster tracked as UNK_MassTraction has been exploiting vulnerabilities in Roundcube webmail servers at academic institutions in the U.S. and Canada since May 2026. The attackers target physics and engineering departments, deploying malware to steal credentials and establish persistent access. Exploitation involves CVE-2024-42009 and CVE-2025-49113 to deploy backdoors such as IceCube, SquareShell, and VShell. Proofpoint attributes the activity to a likely China-aligned espionage group based on infrastructure overlap and linguistic artifacts, though confidence is moderate.
AI-extracted · verify before operational use
Extracted Entities 3 found
MITRE ATT&CK TTPs 8 techniques
T1027 Obfuscated Files or Information · Defense Evasion T1055 Process Injection · Defense Evasion T1059.001 PowerShell · Execution T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1087.002 Domain Account · Discovery T1090 Proxy · Command And Control T1190 Exploit Public-Facing Application · Initial Access