Security Suspected Chinese snoops caught breaking into universities' Roundcube mailservers Proofpoint researcher tells The Reg: 'We estimate the total volume of targets would be a few dozen' Jessica Lyons Jessica Lyons Cybersecurity Editor Published wed 8 Jul 2026 // 22:35 UTC Suspected Chinese spies have been breaking into major US and Canadian universities since May, exploiting vulns in Roundcube mailservers to steal data belonging to physics and engineering administrators and professors, according to Proofpoint threat researchers. Proofpoint directly observed âless than 10â universities targeted in these intrusions, Greg Lesnewich, principal threat research engineer at Proofpoint, told The Register . âWe estimate the total volume of targets would be a few dozen universities, but stress that this is at best a guess, not substantiated by our data.â While the most recent sighting occurred in early June, âwe believe it is likely that the campaign is ongoing,â Lesnewich said. REG AD The email security shop tracks the crew as UNK_MassTraction, and says that it focuses on individuals in departments with national security ties or in astrophysics and particle physics - all topics that support Beijingâs intelligence-gathering goals and, as such, are frequently targeted by government-backed cyber goons . REG AD To gain initial access, the intruders exploit CVE-2024-42009 , a cross-site scripting vulnerability in Roundcube that only requires that the email is opened in the mail client to achieve access to the server. âThe targeted departments were likely specifically chosen because they were all running [vulnerable] versions of Roundcube ⊠indicating that UNK_MassTraction had conducted reconnaissance into the targets prior to conducting the campaign,â the threat hunters wrote in a Tuesday blog. While the espionage activity is similar to an earlier campaign disclosed by Trellix that used a filename parsing vulnerability to deliver VShell malware, a Go-based backdoor used primarily by Chinese APT groups for remote access, file operations, and post-exploitation control, Proofpoint says it cannot definitely link this earlier activity to UNK_MassTraction. It all starts with a generic phishing email The UNK_MassTraction attack chain begins with a phishing email sent to university departments from both compromised legitimate senders and abused domains vulnerable to spoofing. According to the threat hunters, the lures are generic, sometimes purporting to be a university marketing message, and this could imply âa larger targeting swathâ than Proofpoint observed. It could also indicate âan attempt to resemble marketing or spam content because targets may open the email but ultimately overlook it (and not investigate it), which is still sufficient for the actor to gain access,â they wrote. Opening the email triggers CVE-2024-42009. The bug abuses a desanitization issue, and can allow remote attackers to steal and send messages. Once the user opens the email in the webmail client of a vulnerable Roundcube instance, a JavaScript loader stored in the message body executes, and allows the attacker to remotely deliver a fully functioning stealer called IceCube. REG AD IceCube first escapes Roundcube's iFrame instantiation via DOM traversal , which gives the stealer access to the entire Document Object Model (DOM) in the browser and Roundcube authentication session. Then it sets to work stealing usernames, passwords, session tokens, and cookies, and it also conducts reconnaissance against the browser, collecting info on the language in use, screen size, and form field values. The stealer sends this initial data to the attackerâs command-and-control servers via HTTP POST, and then uses the sessionâs CSRF token to set up gadgets to exploit another Roundcube vulnerability. This one, a deserialization exploit tracked as CVE-2025-49113 , allows the miscreants to install a webshell called SquareShell that allows for remote code execution, as well as a VShell implant. Proofpoint notes that its researchers scanned for SquareShell on compromised servers, and coordinated with government and industry partners to notify the identified victims. As of June, the threat hunters also observed the attackers introducing a fallback channel in case the original webshell deployment didnât work. Previously, if the webshell didnât execute, the attack chain would fail. MORE CONTEXT PRC-linked spies hid inside medical and military networks for more than a year, snooping through Gmail and stealing data Notepad++ hijacking blamed on Chinese Lotus Blossom crew behind Chrysalis backdoor Chinese spies used Maduro's capture as a lure to phish US govt agencies China's Ink Dragon hides out in European government networks More links to PRC-backed spies The fallback channel executes a shell script that sets up the execution of another loader that Google tracks as SnowLight . âThe shell script has been used in other exploit-driven intrusions by Chinese adversaries, likely indicating a privately shared capability,â Proofpoint notes. Proofpointâs security sleuths say that they have identified âseveral casesâ of virtual private server IP addresses within the headers of the phishing emails that belong to a âcovert infrastructure network likely used by multiple China-aligned threat actors.â REG AD The access to this network, along with the low-volume targeting of US and Canadian universities, VShell usage, and Chinese-language artifacts within the phishing emails, âleads us to assess that UNK_MassTraction is likely a China-aligned espionage motivated threat actor that has demonstrated moderate operational security awareness,â the team wrote.Âź security cyber-crime REG AD SOFTWARE Mozilla speeds Firefox release schedule to biweekly And what to expect in Firefox 153 as the next ESR release gets close off-prem Billing software error sends billion-dollar AWS estimates Amazon asks users not to panic as it works to fix the bug Gobi X: Creating more energy for AI, not taking it from society PARTNER CONTENT: How Envision is reversing the datacenter playbook by making computing chase abundant desert power, not the other way around security AI spam filters are getting suckered by old-school text salting Turns out decades-old email tricks still work against some LLM-powered email filters PaaS + IaaS Amazon Web Services' most vocal customer now runs EC2 Retail foundation leader Dave Treadwell takes over as senior leader and 19-year vet Dave Brown departs for pastures unknown SAAS Microsoft gives admins Exchange Online breathing room Retirement of PowerShell -Credential parameter pushed back to the end of 2026 MOST POPULAR ai and ml Linus Torvalds tells AI haters to fork off AI and ml Musk promises purge after Grok Build caught sending entire repos to the cloud DevOps HTTP gets a QUERY method so complex searches can stop pretending to be POST DEVOPS Zig creator calls Bunâs Claude Rust rewrite âunreviewed slopâ OS PLATFORMS Torvalds challenged the haters to fork Linux. Someone said 'hold my beer' AI AI and ML OpenAI admits GPT-5.6 occasionally deletes files â but it's an 'honest mistake' Data purges deemed an example of 'misaligned behavior' that upstart is working to avoid AI and ML Researcher poisons open-weight AI model for under $100 Models demand trust without offering verification SYSTEMS TSMC's $265B US fab pledge is the outline of a concept of a plan Beware of fab makers bearing press releases AI and ml Former OpenAI CTO does what Altman won't, releases a frontier AI model that's actually open Thinking Machines' first open weights model is a 975 billion parameter alternative to Chinese LLMs ai and ml Cadence's AuraStack agent melds AI with HPC to speed PCB, advanced packaging design One-two punch offers a glimpse of how low-precision AI can complement high-precision simulations Infosec Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career FOSS A moment of silence, please, for the final release of Debian on x86-32 New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websites Flaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server â implemented directly in assembly Joins yserver, Phoenix, and of course XLibre â and outlier Arcan Cinnamon 6.8 will support Wayland â if you want it Next version of Linux Mintâs desktop has both kinds of display server KDE Plasma users face a dire omen of change: 6.6.6 arrives 6.7 is now current, and in 6.8 you're getting Wayland whether you like it or not Collabora releases CODE 26.04 as rivalry between FOSS cloudy office suites heats up Now with Markdown support and smarter formula error handling â plus integrated AI, though it's off by default
A suspected Chinese APT group is exploiting a critical cross-site scripting vulnerability (CVE-2024-42009, CVSS 9.3) in Roundcube Webmail to compromise university mailservers via phishing emails, gaining access simply when a user opens a malicious message. The vulnerability affects Roundcube Webmail versions earlier than 1.5.8, and versions 1.6.0 through 1.6.7; it is fixed in versions 1.5.8 and 1.6.8.