AUTO-UPDATED

Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities

A China-aligned threat cluster identified as UNK_MassTraction is exploiting critical vulnerabilities in Roundcube webmail software to target physics and engineering departments at universities in the United States and Canada.

Key Points

  • The campaign exploits CVE-2024-42009 and CVE-2025-49113 to gain unauthorized access to university mail servers.
  • Attackers deploy the IceCube malware to siphon credentials, 2FA tokens, and browser data from targeted administrators and professors.
  • Successful breaches result in the installation of VShell or SquareShell, providing persistent remote code execution capabilities.
  • The threat actor uses sophisticated "deferred triggers" to maintain infection chains and erase forensic evidence upon user logout.
  • Proofpoint researchers noted the use of the SNOWLIGHT ELF loader, a tool previously associated with other China-nexus hacking groups.

Why it Matters

This campaign highlights a shift in targeting as Chinese-aligned actors increasingly treat email servers as critical entry points for network infiltration. Organizations must prioritize securing mail infrastructure with the same rigor applied to VPNs and other edge devices to prevent unauthorized access to sensitive research data.
Internet Published by info@thehackernews.com (The Hacker News)
Read original