UNK_MassTraction: China-Aligned Actor Exploits Roundcube CVE-2024-42009 & CVE-2025-49113 to Deploy IceCube Stealer and VShell Against University Physics Departments — Threadlinqs Intelligence
As of 2026-07-13, UNK_MassTraction: China-Aligned Actor Exploits Roundcube CVE-2024-42009 & CVE-2025-49113 to Deploy IceCube Stealer and VShell Against University Physics Departments is a high-severity campaign threat attributed to UNK_MassTraction (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-1259 · Severity: HIGH · CVSS: 9.9 · Status: ACTIVE · Category: CAMPAIGN
Attribution: UNK_MassTraction · China · ESPIONAGE
Since May 2026, Proofpoint has tracked UNK_MassTraction, a suspected China-aligned espionage threat cluster, exploiting an XSS flaw in Roundcube webmail (CVE-2024-42009) to run the JavaScript stealer
UNK_MassTraction is a suspected China-aligned espionage threat cluster first tracked by Proofpoint beginning in May 2026. The campaign opens with phishing emails sent from compromised third-party mailboxes (e.g. jpcontreras@newfield.cl) and spoofed, DMARC-weak domains, crafted to look like generic marketing/spam so recipients do not scrutinize them. The messages carry a specially crafted HTML body that abuses insufficient sanitization in Roundcube Webmail's mail-display function: an animation-event handler (onanimationstart) executes a decimal-encoded JavaScript loader the moment the message is opened in a vulnerable Roundcube client, tracked as CVE-2024-42009 (CVSS 9.3, CWE-79 stored/reflected XSS).
That loader delivers IceCube, a purpose-built JavaScript credential and session stealer that runs inside the victim's authenticated Roundcube session. IceCube performs DOM traversal to escape iframes, harvests usernames/passwords and any 2FA material entered into the page, steals session and CSRF cookies/tokens, fingerprints the browser (language, screen size, form data), and sets deferred triggers on the logout button and page-close events so it can clean up evidence and destroy forensic traces of the session before the victim notices. Code review of IceCube samples shows verbose, LLM-generated code comments and iterative "phase" markers, suggesting AI-assisted malware development, plus resilient retry/fallback logic for reliability across variable network conditions.
With stolen session material, the actor pivots to a second, more serious Roundcube flaw: CVE-2025-49113 (CVSS 9.9, CWE-502), an insufficiently validated `_from` parameter in `program/actions/settings/upload.php` that allows an authenticated user to trigger PHP object deserialization and reach a gadget chain culminating in `__destruct()`-driven command execution. The actor sends a crafted HTTP POST containing serialized PHP payload data (with a valid CSRF token obtained via the IceCube session hijack) to instantiate the gadget chain and execute arbitrary shell commands on the mail server itself — moving from a client-side webmail compromise to full server-side RCE on the mailserver host.
Server-side access is used to drop SquareShell, a small PHP webshell written to `plugins/newmail_notifier/mail_preview.php` inside the Roundcube plugin directory and timestomped to match the legitimate plugin's modification time to blend in with routine file activity. SquareShell exposes `system`, `passthru`, `exec`, `shell_exec`, `assert`, and `popen` execution primitives to give the operator durable, remotely reachable command execution independent of any further Roundcube exploitation.
Beginning in June 2026 the group introduced a fallback deployment mechanism: rather than relying solely on the PHP webshell, compromised servers are used to pull down and in-memory-load VShell, a mature Go-based, multi-platform (Windows/Linux/macOS) backdoor previously documented in numerous China-nexus campaigns (UNC5174/Uteus, UAT-8302, CL-STA-0048, Earth Lamia's "Operation DRAGONCLONE"). The loader downloaded onto UNK_MassTraction victims is architecture-dependent, checks `/tmp/log_de.log` to avoid duplicate execution, wraps itself with `nohup`, and masquerades in the process table as `[kworker/0:2]` — a well-known VShell evasion signature — to blend into normal Linux kernel worker-thread noise. Once running, VShell gives the operator an interactive shell, port-forwarding, and network-pivoting capability entirely in memory, without touching disk, complicating file-based detection and incident response on university-owned Linux mail infrastructure.
Targeting is unusually narrow and deliberate: rather than broad opportunistic phishing, UNK_MassTraction concentrates on physics and engineering department administrators and professors at US and Canadian universities, prioritizing institutions with astrophysics and particle physics programs carrying national-security relevance (e.g. dual-use resea
Weaknesses (CWE)
CWE-79, CWE-502
Target sectors: higher education, government administration
Target regions: North America
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
CAMPAIGN, HIGH, threat intelligence, cybersecurity, CVE-2024-42009, CVE-2025-49113, T1589, T1586, T1583, T1566, T1190, T1059, T1059, T1204, T1505, T1068