Roundcube of a new, targeted cyberattack attributed to a group with possible ties to China. According to researchers at Proofpoint, the group — known as UNK_MassTraction — is exploiting critical vulnerabilities in the popular open-source webmail software, targeting physics and engineering departments at U.S. and Canadian universities. The campaign was first detected in May 2026 and is a highly sophisticated example of academic-targeted cyberespionage, highlighting once again that educational institutions are a prime target for state-sponsored APT groups.

The attackers are exploiting two critical vulnerabilities: CVE-2024-42009 ( CVSS score 9.3) and CVE-2025-49113 ( CVSS score 9.9). The first concerns a cross-site scripting (XSS) flaw that is triggered once the recipient opens the malicious email in the Roundcube client. This allows arbitrary JavaScript code to be executed in the victim’s browser, paving the way for further exploitation. It is worth noting that both vulnerabilities have already been fixed by the Roundcube developers, which makes it absolutely imperative for any organization using it to update the software. The fact that the attackers chose specific university departments, which were running vulnerable versions, suggests extensive preliminary identification of the targets.
See also: Hackers exploit Roundcube vulnerability to steal credentials
The phishing emails used in the campaign were sent from both compromised senders and domains vulnerable to spoofing due to a lack of DMARC policy . Proofpoint researchers Greg Lesnewich and Mark Kelly note that the use of generic baits suggests broader targeting beyond the cases already identified. The targets include primarily system administrators and professors in departments related to national security or dealing with astrophysics and particle physics — areas of direct strategic value to government intelligence agencies.
Roundcube: How the attack chain works with IceCube
After the XSS vulnerability is successfully exploited, a payload codenamed IceCube. IceCube is designed to steal credentials stored in the browser, including two-factor authentication (2FA) and cookies. It also performs identification by collecting information about the browser language, screen size, and form field values. The data is sent to an external system via an HTTP POST request, allowing attackers to gain a complete picture of the victim's environment without raising suspicion.
IceCube then leverages the session CSRF token to exploit the second vulnerability , CVE-2025-49113 , a critical post-authenticated remote code execution vulnerability in Roundcube with a near-perfect CVSS score . The goal is to gain access to the mail server and install either VShell or a web shell codenamed SquareShell . SquareShell is deployed via a PHP gadget shell command and is accessible at the plugins/newmail_notifier/mail_preview.php endpoint , allowing arbitrary code execution remotely. Its placement in a legitimate plugin directory makes it particularly difficult for traditional security tools to detect.
See also: Hacker sells critical Roundcube webmail exploit
Roundcube, SNOWLIGHT and the connections to Chinese APT groups
In June 2026, the attack chain was enhanced with an alternative method for cases where the SquareShell installation fails. Instead of terminating the attack, a shell script via the Roundcube, which acts as a conduit for an ELF loader known as SNOWLIGHT. SNOWLIGHT has been used in other attacks attributed to Chinese attackers, specifically the UNC5174. The existence of an alternative attack path demonstrates that UNK_MassTraction has invested significantly in the resilience and adaptability of their infrastructure.

The use of both SNOWLIGHT and VShell has previously been linked to UNC5174, suggesting that the shell script may be shared between multiple Chinese groups — similar to ShadowPad and other tools that have been detected in various APT campaigns. The script's primary function is to retrieve a version of SNOWLIGHT compatible with the target system's architecture and then execute it. This pattern of tool sharing between Chinese APT groups makes attribution particularly complex for security analysts.
See also: Hackers Target Uyghurs and Tibetans with MOONSHINE Exploit and DarkNimbus Backdoor
To protect against similar attacks, organizations using Roundcube should take immediate action. First, upgrading to the latest version of the software is absolutely essential, as both vulnerabilities have already been patched. Second, it is recommended to check the logs for suspicious activity in the mail_preview.php endpoint and in the plugin directory in general. Third, implementing a strict DMARC , DKIM , and SPF policy can significantly reduce the risk of spoofing attacks. Finally, enabling multi-factor authentication on all accounts and regularly training staff on phishing issues are key defensive measures. According to The Hacker News, the campaign is still being monitored by security researchers, and it is not excluded that new targets will be identified in the near future.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
