China-aligned attackers have targeted U.S. and Canadian universities, exploiting a chain of vulnerabilities in the Roundcube webmail client to gain unauthorized access to sensitive data and establish persistent footholds within academic networks. The campaign, observed by Proofpoint researchers since May, appears to be ongoing and has primarily focused on physics and engineering departments, with a particular interest in administrators and professors linked to national security or involved in astrophysics and particle physics research.
Proofpoint identified less than ten university victims and estimates that a few dozen institutions may have been compromised. Researchers believe many affected organizations are likely unaware of the intrusion. The attackers leveraged two critical vulnerabilities in Roundcube, an open-source email client, in sequence. The first exploit, identified as CVE-2024-42009, allowed for the execution of JavaScript within a victim's browser. This was followed by the exploitation of CVE-2025-49113, which provided attackers with access to the mail server itself.
The initial point of compromise in this campaign involved a victim simply opening an email. Attackers reportedly used generic lures to prompt this action, initiating the exploit chain. Proofpoint attributes the campaign to a China-aligned threat cluster, designated UNK_MassTraction, due to the use of a known covert network associated with multiple China-aligned groups, an infection chain that ultimately leads to VShell, and the presence of Chinese language artifacts within the phishing emails.
While the attackers' specific objectives remain unclear, the targeting of physics and engineering departments aligns with China's strategic initiatives. Proofpoint researchers have not yet obtained data indicating what specific information may have been exfiltrated, as their observation focused on the initial email delivery and exploitation attempts.
This campaign represents a shift in tactics for China-aligned adversaries, who have historically targeted edge devices like routers and VPN concentrators for network access. Instead of using email for credential harvesting or malware delivery to end-users, this operation utilizes email to compromise the mail server directly, establishing a more foundational presence within the target network.
The exploitation of Roundcube vulnerabilities highlights the ongoing threat posed by compromised webmail clients, which can serve as a critical entry point for sophisticated attackers. The focus on academic institutions involved in sensitive research underscores the persistent interest of nation-state actors in acquiring advanced technological knowledge and data.
Proofpoint's findings come shortly after Google threat hunters reported a separate Chinese state-sponsored espionage group that had maintained a long-term presence within various sectors, including academia, medicine, and defense, for years. The ongoing nature of these campaigns suggests a sustained effort by China-aligned groups to gather intelligence and potentially disrupt research and development in targeted countries.
Further details on the specific impact or data stolen are not yet available, and the investigation into the full scope of the campaign is ongoing. Organizations using Roundcube are advised to ensure their systems are updated to the latest secure versions and to implement robust email security practices.






