Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
Reported exploitedRoundcube webmailUNK_MassTractionOur summary
A suspected China-aligned threat group has been observed targeting Roundcube webmail used by physics and engineering departments at U.S. and Canadian universities, enabling credential theft and persistent access. The campaign chains exploitation of CVE-2024-42009 (XSS) and then leverages CVE-2025-49113 for remote code execution, with payloads such as VShell for post-compromise activity; Proofpoint tracks the activity as UNK_MassTraction. This matters because opening a crafted email in the Roundcube client can trigger access to the mail server, turning email delivery into a practical path to compromise.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.