China-linked hackers breach Roundcube mail at universities
A suspected China-aligned hacking group called UNK_MassTraction has been breaking into Roundcube email servers at physics and engineering departments of US and Canadian universities since May 2026. The attackers exploit known but unpatched Roundcube bugs to steal login credentials and plant a webshell or a backdoor called VShell on the mail servers. Researchers at Proofpoint say the group appears to be using the compromised mail servers as a stepping stone into wider university networks, with a focus on departments tied to national security research and astrophysics.
- Started
- May 1, 2026
- Latest activity
- Jul 8, 2026
- Attributed to
- UNK_MassTraction (China-aligned, suspected)Suspected
- Where
- United States, Canada
- Sectors
- Education
- Scale
- multiple physics and engineering departments at US and Canadian universities, exact number not disclosed
Current status
As of August 10, 2026, no new confirmed activity or official closure has been reported since the August 8 dormant update.
Dormant: No new confirmed activity for a while, and nobody has called an official all clear.
Who is behind it
Proofpoint Threat Research calls the cluster suspected China-aligned based on tooling and targeting, but has not linked it to a known Chinese state group.
Impact
Attackers stole login credentials from university staff and planted persistent backdoors on mail servers, giving them a foothold to move deeper into university networks. No data theft or further network compromise has been publicly confirmed beyond the initial mail server access.
What to do
University IT administrators should patch Roundcube to the latest version and check mail server logs for signs of webshells or the VShell backdoor; there is nothing for individual readers to do.
Timeline
-
Aug 8, 2026
No new confirmed activity reported, so this incident moved to dormant while it stays open.
Dormant -
Jul 8, 2026
BleepingComputer and other outlets reported on the campaign, noting it remained active and the number of affected universities was not disclosed.
Activebleepingcomputer.com -
Jul 7, 2026
Proofpoint published research disclosing the UNK_MassTraction campaign, its use of CVE-2024-42009 and CVE-2025-49113, and its SquareShell and VShell tools.
Activeproofpoint.com -
May 1, 2026
Proofpoint began observing UNK_MassTraction exploiting Roundcube servers at US and Canadian university physics and engineering departments.
Activeproofpoint.com
Sources
- One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation Proofpoint Jul 7, 2026
- Hackers exploit Roundcube flaw to spy on academic researchers BleepingComputer Jul 8, 2026
- Suspected Chinese spies are raiding university mailboxes via a Roundcube flaw The Next Web Jul 9, 2026
- Roundcube webmail hack hits physics departments SecurityOnline Jul 13, 2026
Related reports
- Roundcube webmail hack hits physics departments Jul 13, 2026
- Roundcube email servers hacked to spy on researchers Jul 8, 2026
- Roundcube email bug can let attackers hijack inboxes Jul 7, 2026