Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors unk_masstraction

Also known as: tracked as, Copy Fail 2, Berserk Bear, Energetic Bear, VolatileVenom, Micropsia to execute, Android, iOS platforms, Taidoor, software, applications, Google of China, Lyceum, gas, CVE-2025-49113, Void Arachne, those specializing in astrophysics, particle physics, 560048, BERSERK BEAR, ALLANITE, CASTLE, DYMALLOY, TG-4192, Dragonfly, Crouching Yeti, Group 24, Havex, Koala Team, IRON LIBERTY, G0035, ATK6, ITG15, BROMINE, Blue Kraken, Ghost Blizzard, Palmetto Fusion, Allanite, Hexane

Description

UNK_MassTraction has focused on physics and engineering departments at U.S. and Canadian universities, especially those engaged in research with national‑security relevance such as astrophysics or particle physics. Their campaigns begin with spear‑phishing emails crafted to exploit two critical Roundcube vulnerabilities: the cross‑site scripting flaw CVE-2024-42009, which allows malicious JavaScript to run inside a user’s browser, and the PHP deserialization vulnerability CVE-2025-49113 that can be used to upload or execute code on the mail server. Once the attacker gains execution in a victim’s web session, they inject an IceCube stealer payload that harvests stored credentials, 2‑factor tokens, and authentication cookies. The stealer then waits for browser closure or tab change before re‑attempting exploitation to avoid detection, using deferred triggers on `onanimationstart`. When the conditions are met, the group drops a lightweight PHP web shell named SquareShell onto the Roundcube installation, or loads an in‑memory Go backdoor called VShell. Subsequent persistence is achieved via the web shell and the VShell backdoor’s ability to bind to Windows services. Pivoting from the compromised mail server into the university network is a hallmark of this group: they use authenticated outbound HTTP requests that carry CSRF tokens for C2, and often employ fallback channels such as an architecture‑specific ELF loader called SNOWLIGHT. They also abuse email headers supplied by VPS providers to obfuscate their command-and-control infrastructure. The actors’ operational tempo appears continuous once a victim domain is breached—persistent polling of the mail system, multiple credential‑harvesting attempts, and automated cleanup procedures that remove browser artifacts and delete temporary files, all designed to stay hidden while they remain in control of the campus network.

Goals & Targeting

Targeted Sectors

Education
Manufacturing
Financial services
Defense
Government
Telecommunications
Healthcare
Transportation
Utilities
Critical infrastructure
Construction
Retail
Energy
Information technology
Legal services
Media
Aviation
Oil gas

Targeted Countries / Regions

United States of America
Canada
CN
US
VN
SG
RU
JP
IN
BR
TW
FR
KP
IL
ES
DE
KR

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 3 hours ago

Executive Summary

UNK_MassTraction is a China‑aligned threat actor that has been targeting U.S. and Canadian university mail systems since May 2026, exploiting Roundcube webmail CVEs to steal credentials and pivot into campus networks. The group deploys a sophisticated chain of phishing, JavaScript injection, credential harvesting with IceCube, and server‑side footholds such as SquareShell or the VShell backdoor. Reputable sources confirm rapid patching remains essential, while strict email authentication controls can blunt the initial social‑engineering vector.

Goals & Targeting

UNK_MassTraction’s strategy centers on covert acquisition of privileged credentials from academic research environments tied to national security. By harvesting authentication material from physics and engineering faculties, the actor can gain footholds within institutional networks that house sensitive research data or proprietary experiments. The dual objectives are intelligence gathering—capturing user credentials for future exploitation—and infrastructure expansion—to establish persistent backdoors that enable long‑term persistence and network lateral movement.

Enhanced Description

Key Capabilities

  • Exploits CVE-2024-42009 XSS in Roundcube to inject malicious JavaScript
  • Exploits CVE-2025-49113 deserialization vulnerability to deploy SquareShell webshell or load VShell backdoor into memory
  • Steals credentials, 2FA tokens and authentication cookies using IceCube stealer
  • Employs phishing emails tailored to the Roundcube vulnerabilities
  • Uses deferred triggers monitoring user activity for re‑execution
  • Purges browser artifacts and server traces with cleanup routines
  • Utilizes fallback ELF loader SNOWLIGHT for architecture‑specific delivery
  • Communicates with C2 over HTTPS POST requests carrying CSRF tokens
  • Implements persistence via PHP webshells (SquareShell) or Go backdoor (VShell)
  • Abuses VPS IP addresses in email headers to hide infrastructure
  • Uses image-based steganography hosted on archive.org for covert payload delivery

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. thehackernews.com — Cited by web research for: VolatileVenom
  2. www.cloaked.com — Cited by web research for: CVE-2025-49113
  3. www.cyfirma.com — Cited by web research for: Void Arachne
  4. www.proofpoint.com — Cited by web research for: SquareShell

Intel Summary

40

Techniques

45

Tools

0

Campaigns

42

IOCs

0

Observed Data

11

Tactics

Tags

Critical Infrastructure
Backdoor / C2
APT
espionage
education-sector
nation-state
cyber-espionage

Details

Type
Unknown
Resource Level
Unknown
Primary Motivation
Financial gain
Country of Origin
North Korea (KP)
Confidence
55%
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.