China-linked hackers hit university email servers to spy on physics and defence researchers

Proofpoint says a group it calls UNK_MassTraction is chaining two Roundcube flaws at U.S. and Canadian universities to steal logins and plant backdoors.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 4 min read
Illustration: A dimly lit university physics laboratory at night, empty of people
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Proofpoint has tracked a campaign since May 2024 targeting Roundcube webmail servers at U.S. And Canadian universities.
  • The hackers focus on physics and engineering staff, including people working on astrophysics, particle physics, or national security research.
  • The attack chains two Roundcube flaws, CVE-2024-42009 and CVE-2025-49113, to steal credentials and install backdoors.
  • Proofpoint assesses with low confidence that UNK_MassTraction is China-aligned.
  • Administrators should apply the latest Roundcube patches and treat mail servers as sensitive remote-access systems.

A hacking group that appears to be working on behalf of China is quietly breaking into university email servers to spy on researchers in physics and defence-related science.

Proofpoint calls the group UNK_MassTraction and has been watching the campaign since May 2024. We first covered these intrusions on 7 July 2026 in "Suspected Chinese Hackers Target University Webmail in Credential-Stealing Campaign"; today's Proofpoint findings add the full attack chain and malware detail.

The targets are specific: physics and engineering departments, professors and administrators working on astrophysics, particle physics, or national security research. The universities sit mostly in the United States and Canada.

How did the hackers get in?

They sent malicious emails to accounts running Roundcube, a free webmail program that universities often use to let staff read email in a browser. The messages came from already-compromised accounts or from lookalike domains designed to appear legitimate, and the lure inside was generic.

Victims didn't need to click anything unusual. Opening the email in a vulnerable Roundcube inbox was enough to trigger the attack.

That's because the message exploited CVE-2024-42009, a cross-site scripting flaw in Roundcube. The bug lets an attacker embed hidden code in an email so the victim's own browser executes it when the message is opened. Once that code ran, it fetched a tool Proofpoint calls IceCube.

What does the malware actually steal?

IceCube is built specifically to loot Roundcube accounts. Proofpoint describes it as a fully-featured Roundcube stealer.

It harvests usernames, passwords, session cookies (the small files that keep you logged in), and two-factor authentication codes. Two-factor authentication, or 2FA, is the extra code many services require on top of a password.

IceCube then pushes further. It uses helper components to exploit a second Roundcube bug, CVE-2025-49113, a deserialisation flaw that can let an attacker run their own commands on the mail server itself. If that works, the attackers install SquareShell, a PHP webshell (a hidden remote-control script) that gives them command access to the server. If it doesn't, the malware falls back to a shell script that loads a second backdoor, VShell, directly into the server's memory. VShell is a commodity tool written in Go that provides an interactive command line and the ability to tunnel traffic through the compromised machine; Proofpoint notes it's been used repeatedly by Chinese hacking crews.

Why does Proofpoint suspect China?

Three threads point that way. The attack infrastructure overlaps with a covert hosting network previously tied to multiple China-linked groups. Earlier phishing waves from the same infrastructure carried Chinese-language artefacts. And targeting internet-facing mail servers as a foothold into internal networks is a hallmark of Chinese espionage, a pattern also visible in the 13-month REDCap intrusion we reported on 15 June 2026.

Proofpoint is careful to stress this is a low-confidence assessment, not a firm attribution.

One detail suggests real reconnaissance was done first: the attackers appear to have selected servers already known to be vulnerable to both CVE-2024-42009 and CVE-2025-49113 before launching.

What should universities and staff do?

Administrators running Roundcube should install the latest security updates covering both flaws. Proofpoint's advice is blunt: treat mail servers with the same care as VPNs and other remote-access systems, because that's exactly how attackers are using them.

Affected staff should reset passwords and revoke active sessions. The attackers harvest 2FA codes, so check whether those settings have been changed.

What matters most here is the no-click trigger. There's no phishing link to train people to avoid; a single email view is enough. Patching is the only reliable defence.

© 2026 Threat Vectr