A suspected Chinese espionage group has been breaking into university mail servers across the United States and Canada. It has stolen credentials from staff in physics, engineering, and national security research.

Security firm Proofpoint disclosed the campaign this week, tracking the crew as UNK_MassTraction and dating it to at least May. The Register reported further detail.

Proofpoint has directly observed fewer than ten affected universities. It estimates the true figure is a few dozen. The most recent sighting was in early June, and the activity is likely still going.

One email is enough

The way in is a flaw in Roundcube, a widely used webmail platform. The attackers exploit a cross-site scripting bug, CVE-2024-42009, that runs the moment a target opens a rigged message. No click, no attachment, no password needed.