SquareShell is a PHP web shell used in espionage intrusions against vulnerable Roundcube webmail servers. It has been associated with activity tracked as UNK_MassTraction, a likely China-aligned threat cluster that targeted universities in the United States and Canada, particularly physics, engineering, astrophysics, particle physics, and other research areas with national-security relevance. The malware is deployed after successful exploitation of the Roundcube deserialization vulnerability CVE-2025-49113, typically following earlier compromise of user webmail sessions through CVE-2024-42009 and the IceCube credential-stealing payload.
SquareShell provides remote command execution on the compromised mail server, giving operators server-side access that can be used as a foothold for broader intrusion activity. Reported implementations support multiple PHP command-execution functions and have been modified to blend into the environment through timestomping. In the observed campaigns, SquareShell served as the preferred server-resident access mechanism, while operators used VShell as a fallback implant when web shell deployment failed. The broader intrusion chain indicates use of compromised or spoofed email senders, targeted phishing, credential theft, session theft, reconnaissance, and post-compromise pivoting from exposed mail infrastructure into internal networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
После сбора данных IceCube использует вспомогательные компоненты для эксплуатации критической уязвимости десериализации в Roundcube — CVE-2025-49113. С ее помощью атакующие пытаются установить PHP-веб-шелл SquareShell, который позволяет удаленно выполнять команды. | С ее помощью атакующие пытаются установить PHP-веб-шелл SquareShell, который позволяет удаленно выполнять команды.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNK_MassTraction repeatedly exploited Roundcube vulnerabilities to infiltrate university networks and used IceCube, SquareShell, and VShell.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
сам просмотр письма в уязвимой версии Roundcube запускает эксплуатацию старого XSS-бага CVE-2024-42009... После сбора данных IceCube использует вспомогательные компоненты для эксплуатации критической уязвимости десериализации в Roundcube — CVE-2025-49113.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool or malware used after exploiting Roundcube vulnerabilities to infiltrate university networks.
PHP web shell used post-exploitation on compromised Roundcube servers to enable remote command execution.
A webshell installed after exploitation of Roundcube vulnerabilities to provide attacker access and enable remote code execution on compromised servers.
A PHP webshell with remote code execution capabilities used post-exploitation on compromised Roundcube servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.