2026-07-09NOTABLEexploitedProofpoint: China-aligned cluster turns a viewed email into a Roundcube foothold, XSS-delivered IceCube stealer chains into a deserialization webshell
Roundcube XSS, exploited by FrostyNeighbor / Ghostwriter (UNC1151) for Polish-targeting credential harvesting
cve · CVE-2024-42009 single-source
Coverage
1
first 2026-05-17 → last 2026-07-09
Latest activity
2026-07-09
Proofpoint: China-aligned cluster turns a viewed email into a Roundcube foothold, XSS-delivered IceCube…
Peak priority
notable
1 notable
Targets
education
sectors: education, public-sector, technology · regions: us, europe
Sources cited
1
1 hosts
Action items (2)
Do-now tasks recorded on the entries about CVE-2024-42009, newest first. Check the date before acting on an older one.
- Verify every Roundcube instance (especially research/education and public-sector webmail) is patched against CVE-2024-42009 and CVE-2025-49113, and treat unpatched webmail as an internet-facing edge device on par with a VPN concentrator.2026-07-09CVE-2024-42009 +1
- Hunt the post-exploitation chain on Roundcube servers: unexpected PHP-upload-handler deserialization activity, webshell files planted in plugin directories (timestomped to match legitimate plugins), and Roundcube session termination bursts that force user logout and clear forensic state.2026-07-09CVE-2024-42009 +1
Defender insights
What each entry about CVE-2024-42009 tells a defender to do, newest first.
Triage
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (5 across 4 tactics)
5 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application · Phishing
- ExecutionExploitation for Client Execution
- PersistenceServer Software Component: Web Shell
- StealthReflective Code Loading
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-09/unk-masstraction-roundcube-edge-exploitation · ATT&CK page ↗
T1566Phishing×1
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.
Evidence: 2026-07-09/unk-masstraction-roundcube-edge-exploitation · ATT&CK page ↗
Execution TA0002
T1203Exploitation for Client Execution×1
Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility.
Evidence: 2026-07-09/unk-masstraction-roundcube-edge-exploitation · ATT&CK page ↗
Persistence TA0003
T1505.003Server Software Component: Web Shell×1
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Evidence: 2026-07-09/unk-masstraction-roundcube-edge-exploitation · ATT&CK page ↗
Stealth TA0005
T1620Reflective Code Loading×1
Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules).
Evidence: 2026-07-09/unk-masstraction-roundcube-edge-exploitation · ATT&CK page ↗
Entries about Roundcube XSS, exploited by FrostyNeighbor / Ghostwriter (UNC1151) for Polish-targeting credential harvesting (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- IceCube×1
- Roundcube Crypt_GPG_Engine PHP deserialization RCE - chained by UNK_MassTraction after CVE-2024-42009 XSS (Proofpoint)×1
- Roundcube Webmail×1
- UNK_MassTraction×1
Where this entity is cited
Source distribution
- proofpoint.com1 (100%)