Suspected Chinese Threat Group Exploits Roundcube Vulnerabilities at US and Canadian Universities (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Targets US and Canadian universities, especially physics and engineering departments
- Exploits Roundcube vulnerabilities: CVE-2024-42009 (XSS) and CVE-2025-49113 (deserialization)
- Uses IceCube JavaScript, webshells, and VShell backdoor; assessed as espionage
"Proofpoint tracked a China-aligned threat cluster, UNK_MassTraction, exploiting Roundcube mail server vulnerabilities at US and Canadian universities, targeting physics and engineering departments with national security links. The attackers used CVE-2024-42009 and CVE-2025-49113 to deploy JavaScript payloads (IceCube), webshells, and the VShell backdoor for credential theft and network access. The campaign is assessed as espionage."
no comments yet.