A suspected China-aligned espionage cluster tracked as UNK_MassTraction targeted Roundcube mail servers at U.S. and Canadian universities, focusing on physics and engineering departments, administrators, professors with national security ties, and institutions involved in astrophysics and particle physics research. Proofpoint said the campaign began in May and remains ongoing, with fewer than 10 confirmed victims but a potential impact spanning a few dozen universities. The attackers used compromised or spoofed email accounts in low-volume operations designed to steal sensitive data and establish persistent access inside university networks.
The intrusion chain combined two critical Roundcube flaws, CVE-2024-42009 and CVE-2025-49113, beginning with a malicious email that required only that a target open it to trigger JavaScript in the victim's webmail session. That access was used to deploy the IceCube credential stealer and then gain server-side control through the SquareShell webshell or an in-memory VShell backdoor, enabling the mail server to be used as a pivot into broader campus environments. Proofpoint linked the activity to China-aligned operations based on Chinese-language artifacts, overlap with covert infrastructure used by other China-linked groups, and the use of VShell, while also noting mature tradecraft such as cleanup routines, fallback mechanisms, deferred triggers, timestomping, and in-memory execution.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Proofpoint identified fewer than 10 confirmed university victims and said a few dozen universities may ultimately be affected. The company also scanned compromised servers for the SquareShell webshell and notified victims it identified.
In the campaign, the attackers exploited CVE-2024-42009 and CVE-2025-49113 in sequence, beginning with malicious JavaScript triggered when a victim opened an email and escalating to server-side access. Proofpoint said the chain enabled deployment of the IceCube credential stealer and persistence via the SquareShell webshell or an in-memory VShell backdoor.
Since May 2026, Proofpoint observed a suspected China-aligned espionage cluster targeting Roundcube mailservers at physics and engineering departments in U.S. and Canadian universities. The campaign used low-volume, targeted emails and focused on stealing sensitive data and establishing persistent access.
Proofpoint published research describing the ongoing campaign, tracking the activity cluster as UNK_MassTraction and assessing it as likely China-aligned. The report cited Chinese-language artifacts, use of VShell, targeting patterns, and infrastructure overlap with other China-aligned activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcescworld.com
Open sourcecommunity.gurucul.com
Open sourcetheregister.com
Open sourceblog.talosintelligence.com
Open sourcecensys.com
Open sourceblog.eclecticiq.com
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.