Suspected Chinese snoops caught breaking into universities' Roundcube mailservers

https://image.theregister.com/5223542.jpg?imageId=5223542&x=0&y=17.91&cropw=100&croph=64.18&panox=0&panoy=17.91&panow=100&panoh=64.18&width=1200&height=683

Proofpoint researcher tells The Reg: 'We estimate the total volume of targets would be a few dozen'

Suspected Chinese spies have been breaking into major US and Canadian universities since May, exploiting vulns in Roundcube mailservers to steal data belonging to physics and engineering administrators and professors, according to Proofpoint threat researchers.

Proofpoint directly observed “less than 10” universities targeted in these intrusions, Greg Lesnewich, principal threat research engineer at Proofpoint, told The Register. “We estimate the total volume of targets would be a few dozen universities, but stress that this is at best a guess, not substantiated by our data.”

While the most recent sighting occurred in early June, “we believe it is likely that the campaign is ongoing,” Lesnewich said.

The email security shop tracks the crew as UNK_MassTraction, and says that it focuses on individuals in departments with national security ties or in astrophysics and particle physics...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more