INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Lazarus Group Exploits Roundcube Flaw to Spy on Researchers
| 2026-07-08 18:56 HIGH LOW EXPLOITED VULNERABILITY STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
The suspected Chinese espionage group, UNK_MassTraction, has been linked to a series of phishing attacks targeting major US and Canadian universities. The group's tactics include exploiting vulnerabilities in Roundcube mailservers to steal sensitive data belonging to physics and engineering administrators and professors. Proofpoint threat researchers estimate that the total volume of targets would be a few dozen. UNK_MassTraction is believed to have conducted reconnaissance into the targeted departments prior to conducting the campaign, using vulnerable versions of Roundcube as their entry point. The group's use of Go-based backdoors and VShell malware suggests a sophisticated cyber operation.
Technical Mitigations AI-generated
* Use up-to-date and patched versions of Roundcube: Ensure that the email client is running on a secure version, with all known vulnerabilities fixed. Regularly update the software to prevent exploitation.
* Implement robust authentication and authorization mechanisms: Use strong passwords, multi-factor authentication (MFA), and role-based access control (RBAC) to limit access to sensitive areas of the system.
* Use secure email clients or services: Consider using alternative email clients like Mozilla Thunderbird or Microsoft Outlook that have built-in security features such as encryption and anti-phishing filters.
* Monitor for suspicious activity and report phishing attempts: Keep an eye on your emails and report any suspicious activity to the university's IT department. This can help prevent social engineering attacks from compromising sensitive information.
* Use a web application firewall (WAF) or intrusion detection system (IDS): Consider installing a WAF or IDS to detect and block potential security threats, such as SQL injection or cross-site scripting (XSS), that could be used by hackers.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ma•••••.php
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShadowPadShadowPadCobalt StrikeCobalt Strike
CVE-2025-49113CVE-2025-49113
CVE-2024-42009CVE-2024-42009
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
educationeducation
Incident Timeline
May 2026
Threat actors used compromised Roundcube servers to target administrators and professors in universities with national security ties or departments studying astrophysics and particle physics.
June 7
Threat actors used compromised Roundcube servers to target physics and engineering departments at universities.
June 2026
Threat actors used SquareShell to target universities via vulnerable Roundcube servers.
Click on any entity below to view its context and source!
organisation
SquareShell
The secondary method is said to have been introduced in June 2026, when previously the attack chain would simply exit upon failing to deploy SquareShell.
2026/07/08
Chinese hackers exploited vulnerable Roundcube servers to steal credentials and establish network access at US and Canadian universities.
Click on any entity below to view its context and source!
infrastructure
Roundcube
A China-linked threat cluster has been exploiting vulnerable Roundcube servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware.
Suspected Chinese snoops caught breaking into universities' Roundcube mailservers.
A suspected China-aligned threat cluster has been exploiting vulnerable Roundcube mail servers at universities in the US and Canada to steal credentials and establish network access.
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities.
A suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departments of U.S. and Canadian universities as part of a new campaign.
The development marks the first time a Chinese hacking group has been tied to the exploitation of Roundcube flaws, which have been
traditionally
abused
by
state-sponsored threat actors
from Russia.
Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities.
Hackers exploit Roundcube flaw to spy on academic researchers.
Sample emails from the campaign
Source: Proofpoint
Opening the email in a vulnerable Roundcube webmail client triggers exploitation of a cross-site scripting flaw tracked as CVE-2024-42009, which executes JavaScript code inside the victim’s browser, loading a payload called IceCube.
According to the researchers, IceCube "is a fully-featured Roundcube stealer" that can harvest usernames, passwords, cookies, two-factor authentication (2FA) data, and browser information.
Proofpoint says
that the malware uses "helpers" to exploit a Roundcube deserialization flaw tracked as
CVE-2025-49113
and attempts to install SquareShell, a PHP webshell that includes remote code execution capabilities.
Administrators of Roundcube systems are advised to apply the latest security updates that address the two flaws and treat mail servers with the same diligence they show for VPNs and other remote access nodes.
Security
Suspected Chinese snoops caught breaking into universities' Roundcube mailservers
Proofpoint researcher tells The Reg: 'We estimate the total volume of targets would be a few dozen'
Suspected Chinese spies have been breaking into major US and Canadian universities since May, exploiting vulns in Roundcube mailservers to steal data belonging to physics and engineering administrators and professors, according to Proofpoint threat researchers.
“The targeted departments were likely specifically chosen because they were all running [vulnerable] versions of Roundcube … indicating that UNK_MassTraction had conducted reconnaissance into the targets prior to conducting the campaign,” the threat hunters
wrote
in a Tuesday blog.
To gain initial access, the intruders exploit
CVE-2024-42009
, a cross-site scripting vulnerability in Roundcube that only requires that the email is opened in the mail client to achieve access to the server.
Once the user opens the email in the webmail client of a vulnerable Roundcube instance, a JavaScript loader stored in the message body executes, and allows the attacker to remotely deliver a fully functioning stealer called IceCube.
IceCube first escapes Roundcube's iFrame instantiation via
DOM traversal
, which gives the stealer access to the entire Document Object Model (DOM) in the browser and Roundcube authentication session.
The stealer sends this initial data to the attacker’s command-and-control servers via HTTP POST, and then uses the session’s CSRF token to set up gadgets to exploit another Roundcube vulnerability.
Roundcube Servers Used as Network Entry Points
Proofpoint found that UNK_MassTraction used phishing emails containing malicious content designed to exploit CVE-2024-42009, a cross-site scripting (XSS) vulnerability in Roundcube.
Suspected Chinese Threat Group Targets Universities via Vulnerable Roundcube Servers.
Proofpoint assessed that the attackers likely selected these organizations after identifying vulnerable Roundcube instances.
The campaign used multiple known Roundcube vulnerabilities to compromise mail servers, using stolen credentials and server access as a pathway into victim networks rather than focusing solely on email data theft.
The firm observed the attackers using a range of techniques during the infection chain, including:
Credential theft through malicious JavaScript payloads
Server-side exploitation of vulnerable Roundcube components
Deployment of webshells for remote access
Memory-based execution of the VShell backdoor
Attackers Deploy VShell For Follow-On Access
After gaining access to Roundcube servers, UNK_MassTraction exploited CVE-2025-49113, a deserialization vulnerability, to deploy a webshell or install the VShell backdoor in memory.
While the nature of the cross-site scripting (XSS) exploit is such that it only requires the recipient to open the email in the Roundcube client in order to obtain access to the mail server, it's assessed that the targeted departments were singled out because they were all running versions of Roundcube susceptible to N-day security flaws.
"The actor is likely abusing Roundcube servers as a pivot point to enter target networks, and the operators have deliberately crafted their infection chain to avoid detection," Proofpoint researchers Greg Lesnewich and Mark Kelly said.
In the next step, IceCube leverages the session's CSRF token to weaponize a second post-authenticated remote code execution flaw in Roundcube -
CVE-2025-49113
(CVSS score: 9.9) - with the goal of obtaining a foothold in the mail server and dropping VShell or a web shell dubbed SquareShell in memory.
However, if the web shell installation fails for some reason, the attack chain falls back to an alternate mechanism in which a shell script is executed via the Roundcube vulnerability to ultimately deliver
VShell
.
"If any of those actions are taken, IceCube hooks those events, and re-attempts exploitation of CVE-2025-49113, and beacons to the C&C [command-and-control] that the user left the Roundcube session.
"
Upon completing these actions or running into a timeout, the JavaScript malware destroys user and malware-initiated sessions on the server, causing the user to log out and erase forensic evidence associated with the compromise from the Roundcube server.
Researchers traced the attacks to a pair of critical vulnerabilities in Roundcube, an open-source email client, that were exploited and chained together to steal credentials and gain long-term access.
organisation
VPS
First, the infrastructure used in the attacks overlaps with a covert VPS network previously associated with multiple China-linked actors.
organisation
VShell
While the espionage activity is similar to an earlier campaign
disclosed by Trellix
that used a filename parsing vulnerability to deliver VShell malware, a Go-based backdoor used primarily by Chinese APT groups for remote access, file operations, and post-exploitation control, Proofpoint says it cannot definitely link this earlier activity to UNK_MassTraction.
The firm observed the attackers using a range of techniques during the infection chain, including:
Credential theft through malicious JavaScript payloads
Server-side exploitation of vulnerable Roundcube components
Deployment of webshells for remote access
Memory-based execution of the VShell backdoor
Attackers Deploy VShell For Follow-On Access
After gaining access to Roundcube servers, UNK_MassTraction exploited CVE-2025-49113, a deserialization vulnerability, to deploy a webshell or install the VShell backdoor in memory.
In the next step, IceCube leverages the session's CSRF token to weaponize a second post-authenticated remote code execution flaw in Roundcube -
CVE-2025-49113
(CVSS score: 9.9) - with the goal of obtaining a foothold in the mail server and dropping VShell or a web shell dubbed SquareShell in memory.
Proofpoint attributes the campaign to a China-aligned cluster because the attackers used a known covert network used by multiple China-aligned threat groups, an infection chain leading to VShell and left Chinese language artifacts in the phishing emails.
If successful, the attacker gains remote code execution on the mail server; otherwise, the malware downloads a shell script that loads another payload, VShell, directly in memory.
organisation
Trellix
While the espionage activity is similar to an earlier campaign
disclosed by Trellix
that used a filename parsing vulnerability to deliver VShell malware, a Go-based backdoor used primarily by Chinese APT groups for remote access, file operations, and post-exploitation control, Proofpoint says it cannot definitely link this earlier activity to UNK_MassTraction.
organisation
APT
While the espionage activity is similar to an earlier campaign
disclosed by Trellix
that used a filename parsing vulnerability to deliver VShell malware, a Go-based backdoor used primarily by Chinese APT groups for remote access, file operations, and post-exploitation control, Proofpoint says it cannot definitely link this earlier activity to UNK_MassTraction.
organisation
CVE-2024-42009
Sample emails from the campaign
Source: Proofpoint
Opening the email in a vulnerable Roundcube webmail client triggers exploitation of a cross-site scripting flaw tracked as CVE-2024-42009, which executes JavaScript code inside the victim’s browser, loading a payload called IceCube.
Roundcube Servers Used as Network Entry Points
Proofpoint found that UNK_MassTraction used phishing emails containing malicious content designed to exploit CVE-2024-42009, a cross-site scripting (XSS) vulnerability in Roundcube.
This indicates that the threat actor likely carried out preparatory reconnaissance into these targets to gather information about their environments prior to sending phishing emails that trigger an exploit for CVE-2024-42009 and execute arbitrary JavaScript code in the context of the victim's web browser.
Opening the email triggers CVE-2024-42009.
The threat cluster, which Proofpoint tracks as UNK_MassTraction, exploited
CVE-2024-42009
to execute JavaScript inside the victim’s browser, then exploited
CVE-2025-49113
to gain a foothold in the mailserver.
organisation
IceCube
Sample emails from the campaign
Source: Proofpoint
Opening the email in a vulnerable Roundcube webmail client triggers exploitation of a cross-site scripting flaw tracked as CVE-2024-42009, which executes JavaScript code inside the victim’s browser, loading a payload called IceCube.
Once the user opens the email in the webmail client of a vulnerable Roundcube instance, a JavaScript loader stored in the message body executes, and allows the attacker to remotely deliver a fully functioning stealer called IceCube.
The JavaScript payload, tracked by Proofpoint as IceCube, was used to steal usernames, passwords, cookies and authentication data.
The payload delivered following the exploitation of the XSS flaw, codenamed IceCube, is designed to siphon credential information stored in the browser along with two-factor authentication (2FA) and cookies.
organisation
CVE-2025-49113
Proofpoint says
that the malware uses "helpers" to exploit a Roundcube deserialization flaw tracked as
CVE-2025-49113
and attempts to install SquareShell, a PHP webshell that includes remote code execution capabilities.
The firm observed the attackers using a range of techniques during the infection chain, including:
Credential theft through malicious JavaScript payloads
Server-side exploitation of vulnerable Roundcube components
Deployment of webshells for remote access
Memory-based execution of the VShell backdoor
Attackers Deploy VShell For Follow-On Access
After gaining access to Roundcube servers, UNK_MassTraction exploited CVE-2025-49113, a deserialization vulnerability, to deploy a webshell or install the VShell backdoor in memory.
"If any of those actions are taken, IceCube hooks those events, and re-attempts exploitation of CVE-2025-49113, and beacons to the C&C [command-and-control] that the user left the Roundcube session.
The threat cluster, which Proofpoint tracks as UNK_MassTraction, exploited
CVE-2024-42009
to execute JavaScript inside the victim’s browser, then exploited
CVE-2025-49113
to gain a foothold in the mailserver.
organisation
SquareShell
Proofpoint says
that the malware uses "helpers" to exploit a Roundcube deserialization flaw tracked as
CVE-2025-49113
and attempts to install SquareShell, a PHP webshell that includes remote code execution capabilities.
This one, a deserialization exploit tracked as
CVE-2025-49113
, allows the miscreants to install a webshell called SquareShell that allows for remote code execution, as well as a VShell implant.
organisation
PHP
Proofpoint says
that the malware uses "helpers" to exploit a Roundcube deserialization flaw tracked as
CVE-2025-49113
and attempts to install SquareShell, a PHP webshell that includes remote code execution capabilities.
The web shell, deployed by means of a PHP gadget shell command, is remotely reachable at the endpoint "plugins/newmail_notifier/mail_preview.php" and enables arbitrary code execution.
organisation
Administrators of Roundcube
Administrators of Roundcube systems are advised to apply the latest security updates that address the two flaws and treat mail servers with the same diligence they show for VPNs and other remote access nodes.
organisation
DOM
IceCube first escapes Roundcube's iFrame instantiation via
DOM traversal
, which gives the stealer access to the entire Document Object Model (DOM) in the browser and Roundcube authentication session.
organisation
IP
Proofpoint’s security sleuths say that they have identified “several cases” of virtual private server IP addresses within the headers of the phishing emails that belong to a “covert infrastructure network likely used by multiple China-aligned threat actors.”
infrastructure
Windows
Proofpoint said VShell, a publicly available Go-based remote access tool, has previously been used by China-aligned operators across Windows, Linux and macOS environments.
infrastructure
Linux
Proofpoint said VShell, a publicly available Go-based remote access tool, has previously been used by China-aligned operators across Windows, Linux and macOS environments.
infrastructure
Macos
Proofpoint said VShell, a publicly available Go-based remote access tool, has previously been used by China-aligned operators across Windows, Linux and macOS environments.
organisation
ELF
The shell script acts as a conduit for an ELF loader referred to as
SNOWLIGHT
and has been put to use in other intrusions orchestrated by Chinese adversaries.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
organisation
The Hacker News
"The emails targeting university departments used both compromised senders, as well as abused domains vulnerable to spoofing due to lax DMARC policy to send the emails," the enterprise security company wrote in a technical
report
shared with The Hacker News, adding the use of generic lures indicates a "larger targeting swath" beyond its visibility.
organisation
SnowLight
More links to PRC-backed spies
The fallback channel executes a shell script that sets up the execution of another loader that
Google tracks as SnowLight
.
organisation
CyberScoop
Proofpoint identified less than 10 university victims and estimates a few dozen universities may be impacted, Greg Lesnewich, principal threat researcher at Proofpoint, told CyberScoop.
victims
10 university victims
Proofpoint identified less than 10 university victims and estimates a few dozen universities may be impacted, Greg Lesnewich, principal threat researcher at Proofpoint, told CyberScoop.
Tactical Metrics
Metrics
infrastructure
Roundcube
Affected Product
Click for context!
A China-linked threat cluster has been exploiting vulnerable Roundcube servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware.
Hackers exploit Roundcube flaw to spy on academic researchers.
Sample emails from the campaign
Source: Proofpoint
Opening the email in a vulnerable Roundcube webmail client triggers exploitation of a cross-site scripting flaw tracked as CVE-2024-42009, which executes JavaScript code inside the victim’s brows…
According to the researchers, IceCube "is a fully-featured Roundcube stealer" that can harvest usernames, passwords, cookies, two-factor authentication (2FA) data, and browser information.
Proofpoint says
that the malware uses "helpers" to exploit a Roundcube deserialization flaw tracked as
CVE-2025-49113
and attempts to install SquareShell, a PHP webshell that includes remote code execution capabilities.
Administrators of Roundcube systems are advised to apply the latest security updates that address the two flaws and treat mail servers with the same diligence they show for VPNs and other remote access nodes.
Security
Suspected Chinese snoops caught breaking into universities' Roundcube mailservers
Proofpoint researcher tells The Reg: 'We estimate the total volume of targets would be a few dozen'
Suspected Chinese spies have been breaking into…
“The targeted departments were likely specifically chosen because they were all running [vulnerable] versions of Roundcube … indicating that UNK_MassTraction had conducted reconnaissance into the targets prior to conducting the campaign,” the threa…
Suspected Chinese snoops caught breaking into universities' Roundcube mailservers.
To gain initial access, the intruders exploit
CVE-2024-42009
, a cross-site scripting vulnerability in Roundcube that only requires that the email is opened in the mail client to achieve access to the server.
Once the user opens the email in the webmail client of a vulnerable Roundcube instance, a JavaScript loader stored in the message body executes, and allows the attacker to remotely deliver a fully functioning stealer called IceCube.
IceCube first escapes Roundcube's iFrame instantiation via
DOM traversal
, which gives the stealer access to the entire Document Object Model (DOM) in the browser and Roundcube authentication session.
The stealer sends this initial data to the attacker’s command-and-control servers via HTTP POST, and then uses the session’s CSRF token to set up gadgets to exploit another Roundcube vulnerability.
A suspected China-aligned threat cluster has been exploiting vulnerable Roundcube mail servers at universities in the US and Canada to steal credentials and establish network access.
Roundcube Servers Used as Network Entry Points
Proofpoint found that UNK_MassTraction used phishing emails containing malicious content designed to exploit CVE-2024-42009, a cross-site scripting (XSS) vulnerability in Roundcube.
Suspected Chinese Threat Group Targets Universities via Vulnerable Roundcube Servers.
Proofpoint assessed that the attackers likely selected these organizations after identifying vulnerable Roundcube instances.
The campaign used multiple known Roundcube vulnerabilities to compromise mail servers, using stolen credentials and server access as a pathway into victim networks rather than focusing solely on email data theft.
…chain, including:
Credential theft through malicious JavaScript payloads
Server-side exploitation of vulnerable Roundcube components
Deployment of webshells for remote access
Memory-based execution of the VShell backdoor…
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities.
A suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departments of U.S. and Canadian universities as part of a new campaign.
The development marks the first time a Chinese hacking group has been tied to the exploitation of Roundcube flaws, which have been
traditionally
abused
by
state-sponsored threat actors
from Russia.
…e the nature of the cross-site scripting (XSS) exploit is such that it only requires the recipient to open the email in the Roundcube client in order to obtain access to the mail server, it's assessed that the targeted departments were singled out…
"The actor is likely abusing Roundcube servers as a pivot point to enter target networks, and the operators have deliberately crafted their infection chain to avoid detection," Proofpoint researchers Greg Lesnewich and Mark Kelly said.
…ext step, IceCube leverages the session's CSRF token to weaponize a second post-authenticated remote code execution flaw in Roundcube -
CVE-2025-49113
(CVSS score: 9.9) - with the goal of obtaining a foothold in the mail server and dropping VShel…
However, if the web shell installation fails for some reason, the attack chain falls back to an alternate mechanism in which a shell script is executed via the Roundcube vulnerability to ultimately deliver
VShell
.
"If any of those actions are taken, IceCube hooks those events, and re-attempts exploitation of CVE-2025-49113, and beacons to the C&C [command-and-control] that the user left the Roundcube session.
…completing these actions or running into a timeout, the JavaScript malware destroys user and malware-initiated sessions on the server, causing the user to log out and erase forensic evidence associated with the compromise from the Roundcube server.
Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities.
Researchers traced the attacks to a pair of critical vulnerabilities in Roundcube, an open-source email client, that were exploited and chained together to steal credentials and gain long-term access.
Metrics
infrastructure
Windows
Affected Product
Proofpoint said VShell, a publicly available Go-based remote access tool, has previously been used by China-aligned operators across Windows, Linux and macOS environments.
Metrics
infrastructure
Linux
Affected Product
Proofpoint said VShell, a publicly available Go-based remote access tool, has previously been used by China-aligned operators across Windows, Linux and macOS environments.
Metrics
infrastructure
Macos
Affected Product
Proofpoint said VShell, a publicly available Go-based remote access tool, has previously been used by China-aligned operators across Windows, Linux and macOS environments.
Metrics
victims
10
University Victims
Proofpoint identified less than 10 university victims and estimates a few dozen universities may be impacted, Greg Lesnewich, principal threat researcher at Proofpoint, told CyberScoop.
Intelligence Sources
Infosecurity-Magazine
2026-07-07
Suspected Chinese Threat Group Targets Universities via Vulnerable Roundcube Servers
Infosecurity-Magazine
The Hacker News
2026-07-07
CyberScoop
2026-07-07
The Register - Cybercrime
2026-07-08
Suspected Chinese snoops caught breaking into universities' Roundcube mailservers
The Register - Cybercrime
BleepingComputer
2026-07-08
Hackers exploit Roundcube flaw to spy on academic researchers
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-09T06:00
Comprehensive Tactical Telemetry
Highly Correlated Entities
19x
organisation
Identified Entity
VPS
entity
5x
tactic
Cyber Operation Type
Espionage
tactic
4x
source region
Origin Country
China
country
4x
infrastructure
Affected Product
Roundcube
software
3x
target region
Target Country
China
country
3x
timeline
Temporal Reference
June 7
date
2x
vulnerability
Exploited CVE
CVE-2024-42009
cve
2x
tactic
MITRE ATT&CK Technique
T1059.007 - JavaScript
technique
2x
general metric
%
54
%
2x
general metric
Score
9
score
Contextual Telemetry
Context Block
5 METRICS
industry
Targeted Sector
Government
sector
general metric
Universities
10
universities
malware
Malware Payload
ShadowPad
tool
malware
Offensive Tool
Cobalt Strike
tool
victims
University Victims
10
university victims
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.