Suspected China-Aligned Hackers Exploit Roundcube Flaws
A suspected China-aligned threat activity cluster appears to be exploiting Roundcube webmail software belonging to physics and engineering departments of U.S. and Canadian universities. The exploitation involves critical security flaws, such as CVE-2024-42009, to siphon credentials.
What happened
A suspected China-aligned threat activity cluster, tracked under the moniker UNK_MassTraction by Proofpoint, has reportedly been exploiting Roundcube webmail software at U.S. and Canadian universities since May 2026. The targeted departments include those with national security ties or involved in astrophysics and particle physics research. The exploitation involves critical security flaws, such as CVE-2024-42009, to siphon credentials. The attack begins with malicious emails sent from compromised accounts or spoofed domains, using generic lures. Opening these emails in a vulnerable Roundcube client triggers exploitation of a cross-site scripting flaw. The threat actor is believed to deploy web shells for persistent access or use a known post-exploitation tool called VShell.
Professional software engineers should assess their exposure by checking if their Roundcube installations are running any of the affected versions listed in the threat data. It is recommended to upgrade to the latest version of Roundcube and monitor for any suspicious activity. The primary sources should be consulted for the most current information and detailed technical insights.
How 0Day mitigates this
roundcube is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.