Particle.news
Download on the App Store

China-Aligned Cluster Exploits Roundcube Flaws to Breach U.S. and Canadian Universities

Proofpoint warns the chained exploits let attackers turn exposed Roundcube mail servers into persistent network footholds.

Overview

  • The campaign was first observed in May 2026 and used phishing emails opened in vulnerable Roundcube webmail to trigger a JavaScript stealer called IceCube that harvests session data.
  • Operators then abused a post-auth deserialization flaw in Roundcube to run code on mail servers and install a PHP webshell (SquareShell) or load the VShell backdoor into memory for remote access.
  • Proofpoint tracks the activity as UNK_MassTraction and says it has confirmed fewer than 10 university victims while estimating a few dozen more may be affected, with targeting focused on physics and engineering departments.
  • The attackers built persistence and anti-forensic steps into the chain, including deferred triggers, session cleanup, timestamp changes, and memory-only loaders to hinder detection and forensic collection.
  • Researchers released IPs, file hashes and URLs and urged immediate patching of exposed Roundcube instances plus log and web-directory reviews while noting they cannot confirm if any data was stolen from compromised servers.