{"id":61050,"date":"2026-07-08T21:35:13","date_gmt":"2026-07-08T21:35:13","guid":{"rendered":"https:\/\/www.theregister.com\/a\/5268778"},"modified":"2026-07-08T21:35:13","modified_gmt":"2026-07-08T21:35:13","slug":"suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\/","title":{"rendered":"Suspected Chinese snoops caught breaking into universities&#8217; Roundcube mailservers"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/image.theregister.com\/5223542.jpg?imageId=5223542&amp;x=0&amp;y=17.91&amp;cropw=100&amp;croph=64.18&amp;panox=0&amp;panoy=17.91&amp;panow=100&amp;panoh=64.18&amp;width=1200&amp;height=683\" class=\"ff-og-image-inserted\"><\/div>\n<div data-element-guid=\"d11159dd-82a3-4c53-901c-d41dec75505c\" readability=\"31.451263537906\">\n<p class=\"kicker \">Security<\/p>\n<p class=\"subtitle \">Proofpoint researcher tells The Reg: &#8216;We estimate the total volume of targets would be a few dozen&#8217;<\/p>\n<\/p><\/div>\n<div data-element-guid=\"4c9dc5d9-c886-4348-bf4a-01d0dc71377d\" readability=\"143.36412045538\">\n<p>Suspected Chinese spies have been breaking into major US and Canadian universities since May, exploiting vulns in Roundcube mailservers to steal data belonging to physics and engineering administrators and professors, according to Proofpoint threat researchers.<\/p>\n<p>Proofpoint directly observed \u201cless than 10\u201d universities targeted in these intrusions, Greg Lesnewich, principal threat research engineer at Proofpoint, told <span class=\"italic m-italic \" data-lab-italic=\"italic\">The Register<\/span>. \u201cWe estimate the total volume of targets would be a few dozen universities, but stress that this is at best a guess, not substantiated by our data.\u201d<\/p>\n<p>While the most recent sighting occurred in early June, \u201cwe believe it is likely that the campaign is ongoing,\u201d Lesnewich said.<\/p>\n<p>The email security shop tracks the crew as UNK_MassTraction, and says that it focuses on individuals in departments with national security ties or in astrophysics and particle physics &#8211; all topics that support Beijing\u2019s intelligence-gathering goals and, as such, are <a href=\"https:\/\/www.theregister.com\/research\/2026\/06\/15\/google-says-prc-linked-spies-hid-in-medical-research-networks-for-more-than-a-year\/5254547\">frequently targeted<\/a> by <a href=\"https:\/\/www.theregister.com\/security\/2026\/02\/02\/notepad-hijacking-linked-to-chinese-lotus-blossom-crew\/4829043\">government-backed cyber goons<\/a>.<\/p>\n<p>To gain initial access, the intruders exploit <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2024-42009\" rel=\"nofollow\">CVE-2024-42009<\/a>, a cross-site scripting vulnerability in Roundcube that only requires that the email is opened in the mail client to achieve access to the server.<\/p>\n<p>\u201cThe targeted departments were likely specifically chosen because they were all running [vulnerable] versions of Roundcube \u2026 indicating that UNK_MassTraction had conducted reconnaissance into the targets prior to conducting the campaign,\u201d the threat hunters <a href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/one-email-closer-edge-unkmasstraction-physics-exploitation\" rel=\"nofollow\">wrote<\/a> in a Tuesday blog.&nbsp;<\/p>\n<p>While the espionage activity is similar to an earlier campaign <a href=\"https:\/\/www.trellix.com\/blogs\/research\/the-silent-fileless-threat-of-vshell\/\" rel=\"nofollow\">disclosed by Trellix<\/a> that used a filename parsing vulnerability to deliver VShell malware, a Go-based backdoor used primarily by Chinese APT groups for remote access, file operations, and post-exploitation control, Proofpoint says it cannot definitely link this earlier activity to UNK_MassTraction.<\/p>\n<h3>It all starts with a generic phishing email<\/h3>\n<p>The UNK_MassTraction attack chain begins with a phishing email sent to university departments from both compromised legitimate senders and abused domains vulnerable to spoofing.&nbsp;<\/p>\n<p>According to the threat hunters, the lures are generic, sometimes purporting to be a university marketing message, and this could imply \u201ca larger targeting swath\u201d than Proofpoint observed. It could also indicate \u201can attempt to resemble marketing or spam content because targets may open the email but ultimately overlook it (and not investigate it), which is still sufficient for the actor to gain access,\u201d they wrote.<\/p>\n<p>Opening the email triggers CVE-2024-42009. The bug abuses a desanitization issue, and can allow remote attackers to steal and send messages.&nbsp;<\/p>\n<p>Once the user opens the email in the webmail client of a vulnerable Roundcube instance, a JavaScript loader stored in the message body executes, and allows the attacker to remotely deliver a fully functioning stealer called IceCube.<\/p>\n<p>IceCube first escapes Roundcube&#8217;s iFrame instantiation via <a href=\"https:\/\/medium.com\/@mohanapriyanpriyan4\/dom-traversal-165061ab7254\" rel=\"nofollow\">DOM traversal<\/a>, which gives the stealer access to the entire Document Object Model (DOM) in the browser and Roundcube authentication session.<\/p>\n<p>Then it sets to work stealing usernames, passwords, session tokens, and cookies, and it also conducts reconnaissance against the browser, collecting info on the language in use, screen size, and form field values.&nbsp;<\/p>\n<p>The stealer sends this initial data to the attacker\u2019s command-and-control servers via HTTP POST, and then uses the session\u2019s CSRF token to set up gadgets to exploit another Roundcube vulnerability. This one, a deserialization exploit tracked as <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2025-49113\" rel=\"nofollow\">CVE-2025-49113<\/a>, allows the miscreants to install a webshell called SquareShell that allows for remote code execution, as well as a VShell implant.<\/p>\n<p>Proofpoint notes that its researchers scanned for SquareShell on compromised servers, and coordinated with government and industry partners to notify the identified victims.<\/p>\n<p>As of June, the threat hunters also observed the attackers introducing a fallback channel in case the original webshell deployment didn\u2019t work. Previously, if the webshell didn\u2019t execute, the attack chain would fail.<\/p>\n<div data-element-guid=\"afe083ca-6701-48e9-9bd8-f8827dd7fb42\" class=\"lab4 column articleList layout_vertical imageLayout_left small-12 large-12 small-abs-12 large-abs-12 abs_grid_12 grid-vas-start mobile-grid-vas-start\">\n<div class=\"content border_width_0 border_width_mobile_0 border-radius-48 border-radius-mobile_48\">\n<h2 class=\"article-list-title t19 font-RobotoCondensed\">MORE CONTEXT<\/h2>\n<\/p><\/div>\n<\/div>\n<h3>More links to PRC-backed spies<\/h3>\n<p>The fallback channel executes a shell script that sets up the execution of another loader that <a href=\"https:\/\/www.theregister.com\/security\/2024\/03\/22\/chinese-snoops-exploit-f5-connectwise-bugs-to-sell-access\/762328\">Google tracks as SnowLight<\/a>. \u201cThe shell script has been used in other exploit-driven intrusions by Chinese adversaries, likely indicating a privately shared capability,\u201d Proofpoint notes.<\/p>\n<p>Proofpoint\u2019s security sleuths say that they have identified \u201cseveral cases\u201d of virtual private server IP addresses within the headers of the phishing emails that belong to a \u201ccovert infrastructure network likely used by multiple China-aligned threat actors.\u201d<\/p>\n<p>The access to this network, along with the low-volume targeting of US and Canadian universities, VShell usage, and Chinese-language artifacts within the phishing emails, \u201cleads us to assess that UNK_MassTraction is likely a China-aligned espionage motivated threat actor that has demonstrated moderate operational security awareness,\u201d the team wrote.\u00ae<\/p>\n<\/p><\/div>\n<p><img decoding=\"async\" src=\"https:\/\/image.theregister.com\/?imageId=5223542&#038;width=800\">READ MORE <a href=\"https:\/\/www.theregister.com\/security\/2026\/07\/08\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\/5268778\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Proofpoint researcher tells The Reg: &#8216;We estimate the total volume of targets would be a few dozen&#8217; READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":61051,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[307],"class_list":["post-61050","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register","tag-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Suspected Chinese snoops caught breaking into universities&#039; Roundcube mailservers 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Suspected Chinese snoops caught breaking into universities&#039; Roundcube mailservers 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-08T21:35:13+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/image.theregister.com\/5223542.jpg?imageId=5223542&amp;x=0&amp;y=17.91&amp;cropw=100&amp;croph=64.18&amp;panox=0&amp;panoy=17.91&amp;panow=100&amp;panoh=64.18&amp;width=1200&amp;height=683\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Suspected Chinese snoops caught breaking into universities&#8217; Roundcube mailservers\",\"datePublished\":\"2026-07-08T21:35:13+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\\\/\"},\"wordCount\":785,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers.jpg\",\"keywords\":[\"Security\"],\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\\\/\",\"name\":\"Suspected Chinese snoops caught breaking into universities' Roundcube mailservers 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers.jpg\",\"datePublished\":\"2026-07-08T21:35:13+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers.jpg\",\"width\":100,\"height\":74},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/security\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Suspected Chinese snoops caught breaking into universities&#8217; Roundcube mailservers\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Suspected Chinese snoops caught breaking into universities' Roundcube mailservers 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\/","og_locale":"en_US","og_type":"article","og_title":"Suspected Chinese snoops caught breaking into universities' Roundcube mailservers 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2026-07-08T21:35:13+00:00","og_image":[{"url":"https:\/\/image.theregister.com\/5223542.jpg?imageId=5223542&amp;x=0&amp;y=17.91&amp;cropw=100&amp;croph=64.18&amp;panox=0&amp;panoy=17.91&amp;panow=100&amp;panoh=64.18&amp;width=1200&amp;height=683","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Suspected Chinese snoops caught breaking into universities&#8217; Roundcube mailservers","datePublished":"2026-07-08T21:35:13+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\/"},"wordCount":785,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/07\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers.jpg","keywords":["Security"],"articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\/","url":"https:\/\/www.threatshub.org\/blog\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\/","name":"Suspected Chinese snoops caught breaking into universities' Roundcube mailservers 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/07\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers.jpg","datePublished":"2026-07-08T21:35:13+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/07\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/07\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers.jpg","width":100,"height":74},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/suspected-chinese-snoops-caught-breaking-into-universities-roundcube-mailservers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Security","item":"https:\/\/www.threatshub.org\/blog\/tag\/security\/"},{"@type":"ListItem","position":3,"name":"Suspected Chinese snoops caught breaking into universities&#8217; Roundcube mailservers"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61050","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=61050"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61050\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/61051"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=61050"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=61050"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=61050"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}