UNK_MassTraction Exploits Roundcube Flaws Against US, Canadian Universities

https://hackread.com/wp-content/uploads/2026/07/unk-masstraction-hackers-roundcube-us-canada-universities-1-1024x576.png

Proofpoint has identified a suspected China-aligned espionage group targeting vulnerable Roundcube mail servers at universities in the US and Canada, with activity focused on physics and engineering departments associated with sensitive research.

The operation has specifically focused on administrators and professors in departments with national security ties or in departments that study astrophysics and particle physics.

SecurityProducts & Services

The firm tracks the group as UNK_MassTraction, and the campaign has been active since May 2026.

How the Attack Works

The emails abuse CVE-2024-42009, a cross-site scripting vulnerability in Roundcube’s HTML sanitization. When the email is opened in a vulnerable Roundcube webmail client, an onanimationstart event can trigger embedded JavaScript, which then loads an external JavaScript file and sets the attack chain in motion.

Proofpoint refers to this JavaScript as IceCube. Once loaded, it collects credentials, cookies, and other browser session data. According to researchers, comments found throughout the...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE

Read more