Overview
- The campaign was first observed in May 2026 and used phishing emails opened in vulnerable Roundcube webmail to trigger a JavaScript stealer called IceCube that harvests session data.
- Operators then abused a post-auth deserialization flaw in Roundcube to run code on mail servers and install a PHP webshell (SquareShell) or load the VShell backdoor into memory for remote access.
- Proofpoint tracks the activity as UNK_MassTraction and says it has confirmed fewer than 10 university victims while estimating a few dozen more may be affected, with targeting focused on physics and engineering departments.
- The attackers built persistence and anti-forensic steps into the chain, including deferred triggers, session cleanup, timestamp changes, and memory-only loaders to hinder detection and forensic collection.
- Researchers released IPs, file hashes and URLs and urged immediate patching of exposed Roundcube instances plus log and web-directory reviews while noting they cannot confirm if any data was stolen from compromised servers.