---
schema: 1
kind: threat
title: "UNK_MassTraction: suspected China-aligned actor exploits Roundcube as an edge device, chaining CVE-2024-42009 XSS into CVE-2025-49113 deserialization"
headline: "Proofpoint: China-aligned cluster turns a viewed email into a Roundcube foothold — XSS-delivered IceCube stealer chains into a deserialization webshell"
summary: >
  Proofpoint named UNK_MassTraction, a suspected China-aligned cluster that since
  May 2026 has exploited Roundcube webmail as an edge device against physics/
  engineering departments at US and Canadian universities. A crafted email that
  is merely viewed triggers CVE-2024-42009 (XSS), executing the IceCube stealer
  in-session; IceCube then exploits CVE-2025-49113 (PHP deserialization) to plant
  the SquareShell webshell or load the VShell backdoor in memory. Both CVEs are
  patched — the actionable item is patch-verification and hunting the chain on
  any Roundcube instance, including EU research/education mail.
discovered_at: "2026-07-09T20:42:00Z"
event_date: "2026-07-07"
run_id: 2026-07-09T2009Z-intel
priority: notable
immediate_action: null
tags: [espionage, nation-state, phishing, vulnerabilities, china-nexus]
regions: [us, europe]
sectors: [education, public-sector, technology]
entities: [actor:unk-masstraction, tool:icecube-stealer]
techniques: [T1566, T1203, T1190, T1505.003, T1620]
affected_products: ["Roundcube Webmail"]
cves:
  - id: CVE-2024-42009
    cvss: null
    epss: null
    type: xss
    vector: user-interaction
    auth: pre-auth
    status: [exploited, patch-available]
    affected: "Roundcube (versions vulnerable to CVE-2024-42009)"
    fixed: "vendor-patched (2024)"
  - id: CVE-2025-49113
    cvss: null
    epss: null
    type: deserialization
    vector: zero-click
    auth: post-auth
    status: [exploited, patch-available]
    affected: "Roundcube (versions vulnerable to CVE-2025-49113)"
    fixed: "vendor-patched (2025)"
sources:
  - url: "https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation"
    publisher: "Proofpoint Threat Research"
    date: "2026-07-07"
    role: primary
closed_sources: []
evidence:
  - quote: "The campaign uses an initial cross-site scripting (XSS) vulnerability to execute JavaScript inside of the victim browser."
    publisher: "Proofpoint Threat Research"
  - quote: "IceCube will use what it calls “helpers” to exploit a second Roundcube vulnerability, a deserialization exploit (CVE-2025-49113) that abuses the parsing of the embedded Crypt_GPG_Engine to install a simple webshell we call SquareShell."
    publisher: "Proofpoint Threat Research"
  - quote: "Chinese adversaries have previously used exploits against mailservers in a similar manner: treating them as edge devices to pivot into a target network."
    publisher: "Proofpoint Threat Research"
verification: single-source
sourcing_note: "Single-sourced to Proofpoint at time of writing (SINGLE-SOURCE-OTHER; not a national-CERT carve-out); no independent corroborating write-up found this run. Carried within the developing-story window (published 2026-07-07, campaign ongoing since May 2026)."
confidence: medium
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: B
  credibility: 2
watchlist_hit: false
actions:
  - "Verify every Roundcube instance — especially research/education and public-sector webmail — is patched against CVE-2024-42009 and CVE-2025-49113, and treat unpatched webmail as an internet-facing edge device on par with a VPN concentrator."
  - "Hunt the post-exploitation chain on Roundcube servers: unexpected PHP-upload-handler deserialization activity, webshell files planted in plugin directories (timestomped to match legitimate plugins), and Roundcube session termination bursts that force user logout and clear forensic state."
migrated_from: null
---

Proofpoint Threat Research documented **UNK_MassTraction**, a suspected China-aligned espionage cluster that since May 2026 has targeted physics and engineering departments at US and Canadian universities by exploiting Roundcube webmail as an edge device rather than phishing end users for credentials ([Proofpoint, 2026-07-07](https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation)). The initial vector is **CVE-2024-42009**, a Roundcube XSS that executes attacker JavaScript via the `onanimationstart` handler the moment a crafted email is opened in a vulnerable client — no attachment or link click required (`T1566` delivery, `T1203` client-side execution). That JavaScript loads **IceCube**, a Roundcube stealer that escapes the mail client's iframe by DOM traversal to reach the full DOM and the authenticated session, harvesting usernames, passwords, 2FA material and cookies; Proofpoint notes IceCube's verbose, well-commented code was likely produced with LLM assistance ([Proofpoint, 2026-07-07](https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation)).

IceCube then uses "helper" modules and the session's CSRF token to trigger **CVE-2025-49113**, a PHP object-deserialization flaw in Roundcube's handling of the embedded `Crypt_GPG_Engine`: a serialized gadget whose `__destruct()` passes `_gpgconf` into a shell-execution path lets the actor plant the **SquareShell** webshell into a plugin directory — timestomped to match a legitimate plugin — for remote code execution (`T1190` server-side exploitation, `T1505.003` web shell) ([Proofpoint, 2026-07-07](https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation)). A fallback channel introduced in June 2026 downloads an architecture-specific ELF loader that reflectively loads the publicly available VShell Go backdoor into memory (`T1620`), spoofing a kernel-worker process name; VShell's interactive shell and port-forwarding are the likely pivot into the target network. IceCube also installs "deferred triggers" that re-attempt exploitation if the user changes tabs or clicks logout, then destroys Roundcube sessions to force logout and remove forensic evidence. Attribution to a China-aligned actor rests on covert-VPS infrastructure reuse across China-aligned actors, Chinese-language build artifacts, and VShell tradecraft precedent (cited as tooling overlap, not the same actor) ([Proofpoint, 2026-07-07](https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation)).

**Defender takeaway:** the confirmed targets are North American universities, but both exploited CVEs are patched upstream and Roundcube is one of the most widely deployed open-source webmail platforms across European academic, research and public-sector mail infrastructure — so the transferable lesson is to defend webmail as an edge device: patch-verify Roundcube and hunt the described chain. **Triage:** the XSS fires on message view, so a benign-looking, low-effort marketing/spam-styled email can be the trigger; the discriminators on the server side are PHP deserialization events from the upload/preferences handler, new files in Roundcube plugin directories whose modification time was copied from a sibling plugin, and abrupt session-destruction bursts — the last of these is the actor removing evidence, not normal user logout.
