Friday, August 28, 2026

China-Aligned UNK_MassTraction Exploits Roundcube Servers to Target Universities

A suspected China-aligned cluster dubbed UNK_MassTraction that is exploiting n-day flaws in Roundcube webmail to compromise physics and engineering departments at U.S. and Canadian universities.

The operators use a two-stage browser-to-server infection chain that begins with a Cross-Site Scripting (XSS) exploit against CVE-2024-42009 to execute JavaScript in the victim’s browser.

Escalate to a credential- and session-theft component, and then pivot to server-side exploitation that results in remote code execution or in-memory backdoor deployment.

The campaign’s initial vector is deceptively simple: lure emails delivered from compromised senders and spoofable domains (owing to weak or absent DMARC) contain HTML that leverages the Roundcube XSS via onanimationstart.

When a vulnerable instance renders the message in its webmail client, the payload runs in the user’s browser. The embedded JavaScript a loader for a next-stage stealer Proofpoint calls IceCube escapes Roundcube’s iframe and harvests usernames, passwords, two-factor tokens, cookies, CSRF tokens, and browser telemetry.

The stolen session data is posted to a command-and-control (C2) endpoint and then used to orchestrate server-side exploitation.

IceCube’s sophistication stands out. The code is modular, heavily commented, and implements “deferred triggers” to re-attempt exploitation if the user navigates away, closes a tab, or attempts logout. It also performs cleanup to remove browser artifacts and contains fallbacks to ensure persistence.

Proofpoint notes stylistic markers that suggest the author used large language model assistance during development.

The pivot to the mailserver is executed via a deserialization vulnerability in the Crypt_GPG_Engine parsing (tracked as CVE-2025-49113).

Beginning in May 2026, Proofpoint observed a new cluster of activity – tracked as UNK_MassTraction – exploiting CVE-2024-42009, a cross-site scripting vulnerability in Roundcube.

UNK_MassTraction infection chain (Source : Proofpoint).
UNK_MassTraction infection chain (Source : Proofpoint).

IceCube crafts PHP serialized gadget payloads that, upon deserialization, trigger __destruct() execution paths to call system utilities and deploy a lightweight webshell identified as SquareShell.

China-Aligned UNK_MassTraction

SquareShell is installed under plugins/newmail_notifier/mail_preview.php, timestomped to mimic legitimate files, and exposes remote code execution through common PHP functions (system, passthru, exec, shell_exec, assert, popen).

Where webshell deployment fails, the chain falls back to a shell script that fetches and executes an architecture-specific ELF loader, which then loads VShell into memory.

VShell an implant written in Go and previously observed across Linux, macOS, and Windows intrusions is used here as an in-memory backdoor.

The loader spoofs a benign process name (for example, kworker/0:2), checks for existing markers to prevent duplicate execution, and connects to a C2 to fetch and fexecve() the backdoor.

VShell’s interactive shell and port-forwarding capabilities make it an effective tool to pivot from the compromised mailserver into internal research networks.

Attribution indicators include Chinese-language artifacts embedded in HTML, reuse of covert VPS infrastructure linked to other China-aligned actors.

VShell loader bash script (Source : Proofpoint).
VShell loader bash script (Source : Proofpoint).

The selection of low-volume, high-value academic targets studying astrophysics, particle physics, and other areas with potential national-security relevance, and the use of VShell components previously associated with Chinese espionage activity.

Proofpoint also highlights similarities to past campaigns that used filename-parsing or deserialization bugs to deliver VShell, though no direct link to those incidents has been established.

Defenders should treat exposed Roundcube instances as high-value edge access points. Immediate mitigations include patching CVE-2024-42009 and CVE-2025-49113.

Enforcing strict DMARC/DMARC alignment to reduce spoofed email delivery, rotating credentials and invalidating active sessions after suspected exposure, searching for timestomped webshells at plugins/newmail_notifier/mail_preview.php, and monitoring for in-memory VShell indicators and anomalous outgoing C2 traffic.

Proofpoint coordinated disclosure and scanning with government and industry partners; operators are likely to iterate on fallbacks and payload delivery, so defenders must assume continued exploitation attempts.

IOCs

IndicatorTypeDescriptionFirst Seen
jpcontreras@newfield[.]clEmail addressCompromised email addressMay 2026
45.150.109[.]151IP addressIceCube JavaScript backdoor delivery and C&CMay 2026
194.213.18[.]133IP addressIceCube JavaScript backdoor delivery and C&CJune 2026
45.86.229[.]111IP addressVShell C&C serverJune 2026
hxxps://45.150.109[.]151.sslip.io:23088/app/js/jquery.min.jsURLIceCube JavaScript backdoor delivery and C&CMay 2026
hxxps://194.213.18[.]133.sslip.io:23088/app/js/jquery.min.jsURLIceCube JavaScript backdoor delivery and C&CJune 2026
hxxps://45.150.109[.]151.sslip.io:23088URLIceCube JavaScript backdoor delivery and C&CMay 2026
hxxps://194.213.18[.]133.sslip.io:23088URLIceCube JavaScript backdoor delivery and C&CJune 2026
hxxp://45.86.229[.]111/slw:8080URLVShell delivery URLJune 2026 
a02f124c5ce4180bd130a62ee03262f399c33491de3aed36e0b15155ae4926c0SHA256IceCube stealerJune 2026

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop Accepting SLAs Written for 2019 SOCs – Here’s the 2026 AI SLA Vendor Checklist – Download Free AI SOC SLA Guide

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against AI Infrastructure

Attackers are increasingly treating AI infrastructure as a high-value...

700 OpenAI Agents Coordinate Attack on Hugging Face and Gain Remote Code Execution

OpenAI’s ExploitGym evaluation environment reportedly became the site of...

Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit

A newly analyzed phishing operation is using server-side polymorphism...

Critical WordPress Plugin Flaw Allows Unauthenticated Administrator Account Takeover

A critical authentication bypass vulnerability has been identified in...

ServiceNow Patches Critical Flaws Enabling Unauthenticated RCE and SQL Injection

ServiceNow has issued security advisories for four vulnerabilities, including...

Researchers Execute Code Inside Fortune 500 Companies via AI Agent llms.txt Files

Security researchers have shown that AI coding agents can...

BlueDelta Targets Defense and Diplomatic Organizations With HOOKEDGE Malware

Russian state-linked threat actor BlueDelta has launched a renewed...

Related Articles

Recent News