IceCube is a malware name used for two distinct espionage-related implants in separate contexts. The better-known current usage refers to a JavaScript-based Roundcube-focused stealer used in a suspected China-aligned campaign against vulnerable university webmail servers in the United States and Canada. In that activity, phishing emails were crafted so that merely opening the message in a vulnerable Roundcube instance triggered exploitation of CVE-2024-42009, executing attacker-controlled JavaScript in the victim’s browser. IceCube then escaped Roundcube’s iframe context through DOM traversal, accessed the broader browser DOM and authenticated Roundcube session, and harvested usernames, passwords, session tokens, cookies, two-factor authentication material, browser language, screen size, and form field values. It also used the compromised session and CSRF material to facilitate follow-on exploitation of CVE-2025-49113 in attempts to gain server-side execution and deploy additional tooling such as SquareShell or VShell. The campaign was tracked as UNK_MassTraction and targeted physics, engineering, astrophysics, particle physics, and national-security-related research organizations, with attribution assessed at low confidence as China-aligned.
The name IceCube also appears as a plugin package within the older Android MOONSHINE surveillance framework associated with the POISON CARP campaign targeting Tibetan organizations. In that context, IceCube was not the primary implant but an auxiliary Android plugin that extended surveillance functions, including camera access, microphone recording, screenshots, notifications, and shell command execution. Because the same name is used for unrelated malware components, analysts should disambiguate IceCube by campaign and platform before use.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
После сбора данных IceCube использует вспомогательные компоненты для эксплуатации критической уязвимости десериализации в Roundcube — CVE-2025-49113. С ее помощью атакующие пытаются установить PHP-веб-шелл SquareShell, который позволяет удаленно выполнять команды. | С помощью этой уязвимости злоумышленники выполняют JavaScript в браузере жертвы и загружают пейлоад IceCube, который исследователи называют полноценным стилером для Roundcube.
сам просмотр письма в уязвимой версии Roundcube запускает эксплуатацию старого XSS-бага CVE-2024-42009. С помощью этой уязвимости злоумышленники выполняют JavaScript в браузере жертвы и загружают пейлоад IceCube | С помощью этой уязвимости злоумышленники выполняют JavaScript в браузере жертвы и загружают пейлоад IceCube, который исследователи называют полноценным стилером для Roundcube.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
С помощью этой уязвимости злоумышленники выполняют JavaScript в браузере жертвы и загружают пейлоад IceCube, который исследователи называют полноценным стилером для Roundcube.
The IceCube.jar plugin package added further functionality: CAMERA: List available cameras and take pictures NOTIFICATION: Show a notification on the phone RECORD: Record audio from the microphone SCREEN_SNAP: Take screenshots SHELL: Execute a shell command
11 distinct techniques documented for this family, organized by ATT&CK tactic.
сам просмотр письма в уязвимой версии Roundcube запускает эксплуатацию старого XSS-бага CVE-2024-42009... После сбора данных IceCube использует вспомогательные компоненты для эксплуатации критической уязвимости десериализации в Roundcube — CVE-2025-49113.
IceCube 'is a fully-featured Roundcube stealer' that can harvest usernames, passwords, cookies, two-factor authentication (2FA) data, and browser information.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stealer targeting Roundcube that steals usernames, passwords, cookies, two-factor authentication data, and browser information; it also uses auxiliary components to help exploit a Roundcube deserialization flaw for further compromise.
A fully featured Roundcube stealer that harvests usernames, passwords, cookies, two-factor authentication data, and browser information.
A stealer delivered through exploited Roundcube webmail sessions that escapes the Roundcube iFrame context, accesses the full DOM and authenticated session, and steals usernames, passwords, session tokens, cookies, and browser reconnaissance data before exfiltrating it to C2 via HTTP POST.
A JavaScript Roundcube-focused stealer/backdoor that escapes the mail client's iFrame, steals usernames, passwords, two-factor authentication material, cookies, and browser reconnaissance data, then uses the session CSRF token to exploit a second Roundcube vulnerability to gain server-side foothold via webshell deployment or fallback payload delivery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.