Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
A China-aligned threat actor cluster, tracked as UNC5174 and linked to ShadowPad, has been exploiting vulnerabilities in Roundcube webmail software at U.S. and Canadian universities. The campaign leverages CVE-2024-42009 and CVE-2025-49113 to gain access, deploying tools like VShell and SquareShell to establish a foothold and conduct reconnaissance. The actors use sophisticated techniques, including 'deferred triggers' and a Go-based remote administration tool (VShell) to maintain persistence and evade detection, marking the first known instance of a Chinese group targeting Roundcube in this manner.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
