Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation

45.86.229.111

TLP:CLEAR
Active

IPv4 Address

Description

Since May 2026, a suspected China-aligned threat cluster named UNK_MassTraction has been exploiting Roundcube mailservers at physics and engineering departments of US and Canadian universities. The campaigns exploit multiple n-day vulnerabilities including CVE-2024-42009 and CVE-2025-49113 to steal credentials and deploy either a webshell called SquareShell or the VShell backdoor into server memory. The actor uses an initial cross-site scripting vulnerability to execute JavaScript, then deploys IceCube stealer to harvest authentication material before pivoting server-side through deserialization exploits. The operators deliberately crafted their infection chain with mature tooling to avoid detection, using Roundcube servers as pivot points to enter target networks. The targeting focuses on departments with national security ties or those studying astrophysics and particle physics.

Sightings (0)

No sightings recorded yet

Details

Name / Label
One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation
Pattern Type
STIX
Confidence
75%
Valid From
Jul 12, 2026 03:08
Total Sightings
0
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 45.86.229.111

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.