CVE
CVE-2025-49113
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
Exploitation IoCs 12
Domain easysend[.]co
Domain enveil[.]online
Domain envell[.]xyz
Domain uxtramine[.]org
Filename InitTest.dll
Filename NppExport.dll
Filename OneScreenCapture64.dll
Filename Release_GetInfoPlugin_x64.dll
Filename Release_PvPlugin_x64.dll
Filename RemoteLibUpdater.exe
Filename libmupdf.dll
Filename updater.rar
MITRE ATT&CK TTPs 10
T1055 T1059.001 T1071.001 T1085 T1087.002 T1090 T1134 T1203 T1218 T1480
Process Injection
Defense Evasion
PowerShell
Execution
Web Protocols
Command And Control
T1085
Domain Account
Discovery
Proxy
Command And Control
Access Token Manipulation
Defense Evasion
Exploitation for Client Execution
Execution
System Binary Proxy Execution
Defense Evasion
Execution Guardrails
Defense Evasion
Source Articles
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
The North Korean threat actor Lazarus Group has exploited a Windows zero-day vulnerability, CVE-2026-68820, in the AFD.sys driver to escalate privileges to SYSTEM and deploy a new in-memory backdoor named Troy. The attack is part of Operation Dream Job, a long-running cyber espionage campaign using fake job offers on LinkedIn to lure victims into downloading trojanized software or opening malicious PDFs. Two infection chains were observed: one using DLL side-loading with the malicious libmupdf.dll and another via a trojanized SecurityPDF viewer that triggers payload execution upon detecting a specific marker in a PDF. The attackers also use compromised legitimate infrastructure, including WordPress, SharePoint, and vulnerable Roundcube servers (CVE-2025-49113), to host C2 communications and distribute the ForestTiger (ScoringMathTea) backdoor.
hacker-news Aug 12, 2026
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
A Russia-aligned threat cluster known as UAC-0099 is distributing a malicious Notepad++ plugin to deliver MATCHBOIL.V2 malware, a modified version of the C#-based loader MATCHBOIL. The attack begins with a phishing email containing an image that leads to a shortened URL, which redirects to a file-sharing service hosting a malicious ZIP file. The ZIP contains a VBScript that executes a decoy PDF while silently deploying a malicious DLL and additional payloads, including RemoteLibUpdater.exe (BURNYBEAR) and InitTest.dll. The campaign aims to establish persistence and conduct espionage, with no financial motive observed.
hacker-news Jul 24, 2026
Hackers exploit Roundcube flaw to spy on academic researchers
A China-linked threat cluster tracked as UNK_MassTraction has been exploiting vulnerabilities in Roundcube webmail servers at academic institutions in the U.S. and Canada since May 2026. The attackers target physics and engineering departments, deploying malware to steal credentials and establish persistent access. Exploitation involves CVE-2024-42009 and CVE-2025-49113 to deploy backdoors such as IceCube, SquareShell, and VShell. Proofpoint attributes the activity to a likely China-aligned espionage group based on infrastructure overlap and linguistic artifacts, though confidence is moderate.
bleeping-computer Jul 8, 2026