Also known as: tracked as, Copy Fail 2, Berserk Bear, Energetic Bear, VolatileVenom, Micropsia to execute, Android, iOS platforms, Taidoor, software, applications, Google of China, Lyceum, gas, CVE-2025-49113, Void Arachne, those specializing in astrophysics, particle physics, 560048, BERSERK BEAR, ALLANITE, CASTLE, DYMALLOY, TG-4192, Dragonfly, Crouching Yeti, Group 24, Havex, Koala Team, IRON LIBERTY, G0035, ATK6, ITG15, BROMINE, Blue Kraken, Ghost Blizzard, Palmetto Fusion, Allanite, Hexane
UNK_MassTraction has focused on physics and engineering departments at U.S. and Canadian universities, especially those engaged in research with national‑security relevance such as astrophysics or particle physics. Their campaigns begin with spear‑phishing emails crafted to exploit two critical Roundcube vulnerabilities: the cross‑site scripting flaw CVE-2024-42009, which allows malicious JavaScript to run inside a user’s browser, and the PHP deserialization vulnerability CVE-2025-49113 that can be used to upload or execute code on the mail server. Once the attacker gains execution in a victim’s web session, they inject an IceCube stealer payload that harvests stored credentials, 2‑factor tokens, and authentication cookies. The stealer then waits for browser closure or tab change before re‑attempting exploitation to avoid detection, using deferred triggers on `onanimationstart`. When the conditions are met, the group drops a lightweight PHP web shell named SquareShell onto the Roundcube installation, or loads an in‑memory Go backdoor called VShell. Subsequent persistence is achieved via the web shell and the VShell backdoor’s ability to bind to Windows services. Pivoting from the compromised mail server into the university network is a hallmark of this group: they use authenticated outbound HTTP requests that carry CSRF tokens for C2, and often employ fallback channels such as an architecture‑specific ELF loader called SNOWLIGHT. They also abuse email headers supplied by VPS providers to obfuscate their command-and-control infrastructure. The actors’ operational tempo appears continuous once a victim domain is breached—persistent polling of the mail system, multiple credential‑harvesting attempts, and automated cleanup procedures that remove browser artifacts and delete temporary files, all designed to stay hidden while they remain in control of the campus network.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNK_MassTraction is a China‑aligned threat actor that has been targeting U.S. and Canadian university mail systems since May 2026, exploiting Roundcube webmail CVEs to steal credentials and pivot into campus networks. The group deploys a sophisticated chain of phishing, JavaScript injection, credential harvesting with IceCube, and server‑side footholds such as SquareShell or the VShell backdoor. Reputable sources confirm rapid patching remains essential, while strict email authentication controls can blunt the initial social‑engineering vector.
Goals & Targeting
UNK_MassTraction’s strategy centers on covert acquisition of privileged credentials from academic research environments tied to national security. By harvesting authentication material from physics and engineering faculties, the actor can gain footholds within institutional networks that house sensitive research data or proprietary experiments. The dual objectives are intelligence gathering—capturing user credentials for future exploitation—and infrastructure expansion—to establish persistent backdoors that enable long‑term persistence and network lateral movement.
Enhanced Description
Key Capabilities
No campaigns linked yet.
No observed data linked yet.
40
Techniques
45
Tools
0
Campaigns
42
IOCs
0
Observed Data
11
Tactics