INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Lazarus Group Exploits Roundcube Flaw to Spy on Researchers

| 2026-07-08 18:56 HIGH LOW EXPLOITED VULNERABILITY STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
The suspected Chinese espionage group, UNK_MassTraction, has been linked to a series of phishing attacks targeting major US and Canadian universities. The group's tactics include exploiting vulnerabilities in Roundcube mailservers to steal sensitive data belonging to physics and engineering administrators and professors. Proofpoint threat researchers estimate that the total volume of targets would be a few dozen. UNK_MassTraction is believed to have conducted reconnaissance into the targeted departments prior to conducting the campaign, using vulnerable versions of Roundcube as their entry point. The group's use of Go-based backdoors and VShell malware suggests a sophisticated cyber operation.
Technical Mitigations AI-generated
* Use up-to-date and patched versions of Roundcube: Ensure that the email client is running on a secure version, with all known vulnerabilities fixed. Regularly update the software to prevent exploitation. * Implement robust authentication and authorization mechanisms: Use strong passwords, multi-factor authentication (MFA), and role-based access control (RBAC) to limit access to sensitive areas of the system. * Use secure email clients or services: Consider using alternative email clients like Mozilla Thunderbird or Microsoft Outlook that have built-in security features such as encryption and anti-phishing filters. * Monitor for suspicious activity and report phishing attempts: Keep an eye on your emails and report any suspicious activity to the university's IT department. This can help prevent social engineering attacks from compromising sensitive information. * Use a web application firewall (WAF) or intrusion detection system (IDS): Consider installing a WAF or IDS to detect and block potential security threats, such as SQL injection or cross-site scripting (XSS), that could be used by hackers.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

ma•••••.php
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShadowPadShadowPadCobalt StrikeCobalt Strike CVE-2025-49113CVE-2025-49113 CVE-2024-42009CVE-2024-42009
Target & Sectors
NORTH_AMERICA NORTH_AMERICA educationeducation
Incident Timeline
‎May 2026
Threat actors used compromised Roundcube servers to target administrators and professors in universities with national security ties or departments studying astrophysics and particle physics.
‎June 7
Threat actors used compromised Roundcube servers to target physics and engineering departments at universities.
‎June 2026
Threat actors used SquareShell to target universities via vulnerable Roundcube servers.
organisation SquareShell
‎2026/07/08
Chinese hackers exploited vulnerable Roundcube servers to steal credentials and establish network access at US and Canadian universities.
infrastructure Roundcube
organisation VPS
organisation VShell
organisation Trellix
organisation APT
organisation CVE-2024-42009
organisation IceCube
organisation CVE-2025-49113
organisation SquareShell
organisation PHP
organisation Administrators of Roundcube
organisation DOM
organisation IP
infrastructure Windows
infrastructure Linux
infrastructure Macos
organisation ELF
organisation EDR
organisation The Hacker News
organisation SnowLight
organisation CyberScoop
victims 10 university victims
Tactical Metrics
Metrics
infrastructure
‎Roundcube
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎Macos
Affected Product
Metrics
victims
10
University Victims