IceCube is a JavaScript-based credential-stealing malware used in espionage intrusions against vulnerable Roundcube webmail deployments. It has been associated with the suspected China-aligned cluster UNK_MassTraction, which targeted universities in the United States and Canada, particularly physics, engineering, astrophysics, particle physics, and other research environments with potential national-security relevance. The malware is delivered through phishing emails that exploit the Roundcube cross-site scripting vulnerability CVE-2024-42009 when a victim opens a message in a vulnerable webmail session, enabling attacker-controlled JavaScript to execute in the browser without requiring attachment execution.
Once loaded, IceCube escapes the constrained Roundcube frame context through DOM traversal to access the broader browser DOM and the authenticated Roundcube session. It is designed to steal usernames, passwords, cookies, session tokens, authentication material including two-factor-related data, and browser or environment information such as language, screen characteristics, and form values. The malware also uses stolen session context and anti-CSRF material to support follow-on exploitation of Roundcube server-side vulnerabilities, including attempts to leverage CVE-2025-49113 for deeper compromise. In observed campaigns, successful follow-on activity enabled deployment of server-side access tooling such as SquareShell or fallback loading of VShell, allowing attackers to pivot from webmail compromise into broader network intrusion.
IceCube’s role in these operations is both credential theft and post-exploitation enablement. Its tradecraft includes deferred triggering and session abuse to maximize the chance of successful exploitation while reducing visibility. The malware reflects a broader pattern of treating internet-facing mail infrastructure as an entry point into institutional networks rather than solely as a source of mailbox data. Although the name IceCube also appears in unrelated historical Android plugin nomenclature, the malware most widely recognized under this name in current reporting is the Roundcube-focused JavaScript stealer used by UNK_MassTraction.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Proofpoint found that UNK_MassTraction used phishing emails containing malicious content designed to exploit CVE-2024-42009, a cross-site scripting (XSS) vulnerability in Roundcube. When executed in a vulnerable webmail client, the exploit allowed JavaScript to run in the victim's browser. | The JavaScript payload, tracked by Proofpoint as IceCube, was used to steal usernames, passwords, cookies and authentication data.
UNK_MassTraction exploited CVE-2024-42009 in Roundcube and used IceCube during post-exploitation, where the malware attempted to exploit CVE-2025-49113.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNK_MassTraction repeatedly exploited Roundcube vulnerabilities to infiltrate university networks and used IceCube, SquareShell, and VShell.
The IceCube.jar plugin package added further functionality: CAMERA: List available cameras and take pictures NOTIFICATION: Show a notification on the phone RECORD: Record audio from the microphone SCREEN_SNAP: Take screenshots SHELL: Execute a shell command
11 distinct techniques documented for this family, organized by ATT&CK tactic.
A suspected China-aligned threat cluster has been exploiting vulnerable Roundcube mail servers at universities in the US and Canada to steal credentials and establish network access.
IceCube 'is a fully-featured Roundcube stealer' that can harvest usernames, passwords, cookies, two-factor authentication (2FA) data, and browser information.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool or malware used after exploiting Roundcube vulnerabilities to infiltrate university networks.
Post-exploitation malware used after Roundcube compromise; the malware also attempted to exploit CVE-2025-49113.
Stealer targeting Roundcube that steals usernames, passwords, cookies, two-factor authentication data, and browser information; it also uses auxiliary components to help exploit a Roundcube deserialization flaw for further compromise.
A fully featured Roundcube stealer that harvests usernames, passwords, cookies, two-factor authentication data, and browser information.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.