A China-aligned threat cluster identified as UNK_MassTraction is exploiting critical vulnerabilities in Roundcube webmail software to target physics and engineering departments at universities in the United States and Canada.
Key Points
- The campaign exploits CVE-2024-42009 and CVE-2025-49113 to gain unauthorized access to university mail servers.
- Attackers deploy the IceCube malware to siphon credentials, 2FA tokens, and browser data from targeted administrators and professors.
- Successful breaches result in the installation of VShell or SquareShell, providing persistent remote code execution capabilities.
- The threat actor uses sophisticated "deferred triggers" to maintain infection chains and erase forensic evidence upon user logout.
- Proofpoint researchers noted the use of the SNOWLIGHT ELF loader, a tool previously associated with other China-nexus hacking groups.