0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

Suspected Chinese Threat Group Exploits Roundcube Vulnerabilities at US and Canadian Universities (infosecurity-magazine.com)

· 20d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Targets US and Canadian universities, especially physics and engineering departments
  • Exploits Roundcube vulnerabilities: CVE-2024-42009 (XSS) and CVE-2025-49113 (deserialization)
  • Uses IceCube JavaScript, webshells, and VShell backdoor; assessed as espionage

"Proofpoint tracked a China-aligned threat cluster, UNK_MassTraction, exploiting Roundcube mail server vulnerabilities at US and Canadian universities, targeting physics and engineering departments with national security links. The attackers used CVE-2024-42009 and CVE-2025-49113 to deploy JavaScript payloads (IceCube), webshells, and the VShell backdoor for credential theft and network access. The campaign is assessed as espionage."

Discussion Matrix

0 segments

no comments yet.