Dormant Medium impact Espionage Checked 1w ago

China-linked hackers breach Roundcube mail at universities

A suspected China-aligned hacking group called UNK_MassTraction has been breaking into Roundcube email servers at physics and engineering departments of US and Canadian universities since May 2026. The attackers exploit known but unpatched Roundcube bugs to steal login credentials and plant a webshell or a backdoor called VShell on the mail servers. Researchers at Proofpoint say the group appears to be using the compromised mail servers as a stepping stone into wider university networks, with a focus on departments tied to national security research and astrophysics.

Started
May 1, 2026
Latest activity
Jul 8, 2026
Attributed to
UNK_MassTraction (China-aligned, suspected)Suspected
Where
United States, Canada
Sectors
Education
Scale
multiple physics and engineering departments at US and Canadian universities, exact number not disclosed

Current status

As of August 10, 2026, no new confirmed activity or official closure has been reported since the August 8 dormant update.

Dormant: No new confirmed activity for a while, and nobody has called an official all clear.

Who is behind it

Proofpoint Threat Research calls the cluster suspected China-aligned based on tooling and targeting, but has not linked it to a known Chinese state group.

Impact

Attackers stole login credentials from university staff and planted persistent backdoors on mail servers, giving them a foothold to move deeper into university networks. No data theft or further network compromise has been publicly confirmed beyond the initial mail server access.

What to do

University IT administrators should patch Roundcube to the latest version and check mail server logs for signs of webshells or the VShell backdoor; there is nothing for individual readers to do.

Timeline

  1. Aug 8, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  2. Jul 8, 2026

    BleepingComputer and other outlets reported on the campaign, noting it remained active and the number of affected universities was not disclosed.

    Activebleepingcomputer.com
  3. Jul 7, 2026

    Proofpoint published research disclosing the UNK_MassTraction campaign, its use of CVE-2024-42009 and CVE-2025-49113, and its SquareShell and VShell tools.

    Activeproofpoint.com
  4. May 1, 2026

    Proofpoint began observing UNK_MassTraction exploiting Roundcube servers at US and Canadian university physics and engineering departments.

    Activeproofpoint.com

Sources

Related reports