IceCube is a stealer used in exploit-driven intrusions against vulnerable Roundcube webmail servers. In the observed campaign, suspected China-aligned threat actor UNK_MassTraction targeted major U.S. and Canadian universities, particularly physics and engineering departments, administrators, professors, and organizations tied to astrophysics, particle physics, or national security-related research. Initial access was achieved via phishing emails sent from compromised accounts or spoofed domains; simply opening the message in a vulnerable Roundcube webmail client triggered exploitation of the Roundcube cross-site scripting flaw CVE-2024-42009. The malicious JavaScript loader embedded in the email body then delivered IceCube.
IceCube is described as a fully featured Roundcube-focused stealer. It escapes Roundcube’s iFrame context through DOM traversal, allowing access to the full browser DOM and the authenticated Roundcube session. Reported collection capabilities include usernames, passwords, session tokens, cookies, two-factor authentication data, browser language, screen size, and form field values. Stolen data is sent to attacker command-and-control infrastructure via HTTP POST. IceCube also used the victim session’s CSRF token to help prepare exploitation of a second Roundcube vulnerability, CVE-2025-49113, which was then used to attempt installation of the SquareShell webshell for server-side remote code execution; if that failed, the broader intrusion chain could fall back to loading VShell in memory. Additional observed behavior included deferred triggers that retried exploitation when the user closed the page, changed tabs, moved the mouse out of the browser window, or clicked logout, and destruction of user and malware-initiated sessions after exploitation attempts or timeout to reduce forensic evidence.
The provided content also contains a separate, unrelated reference to an "IceCube.jar" plugin in the MOONSHINE/Scotch Android surveillance framework used in earlier mobile targeting of Tibetan organizations. That plugin added capabilities including listing cameras and taking pictures, showing notifications, recording microphone audio, taking screenshots, and executing shell commands. Based on the supplied content, this mobile plugin reference is distinct from the Roundcube stealer that is the primary malware named IceCube here.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
To gain initial access, the intruders exploit CVE-2024-42009, a cross-site scripting vulnerability in Roundcube that only requires that the email is opened in the mail client to achieve access to the server... Opening the email triggers CVE-2024-42009.
Once the user opens the email in the webmail client of a vulnerable Roundcube instance, a JavaScript loader stored in the message body executes, and allows the attacker to remotely deliver a fully functioning stealer called IceCube.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Once the user opens the email in the webmail client of a vulnerable Roundcube instance, a JavaScript loader stored in the message body executes, and allows the attacker to remotely deliver a fully functioning stealer called IceCube.
The IceCube.jar plugin package added further functionality: CAMERA: List available cameras and take pictures NOTIFICATION: Show a notification on the phone RECORD: Record audio from the microphone SCREEN_SNAP: Take screenshots SHELL: Execute a shell command
11 distinct techniques documented for this family, organized by ATT&CK tactic.
To gain initial access, the intruders exploit CVE-2024-42009, a cross-site scripting vulnerability in Roundcube that only requires that the email is opened in the mail client to achieve access to the server.
IceCube 'is a fully-featured Roundcube stealer' that can harvest usernames, passwords, cookies, two-factor authentication (2FA) data, and browser information.
IceCube first escapes Roundcube's iFrame instantiation via DOM traversal, which gives the stealer access to the entire Document Object Model (DOM) in the browser and Roundcube authentication session. Then it sets to work stealing usernames, passwords, session tokens, and cookies.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A fully featured Roundcube stealer that harvests usernames, passwords, cookies, two-factor authentication data, and browser information.
A stealer delivered through exploited Roundcube webmail sessions that escapes the Roundcube iFrame context, accesses the full DOM and authenticated session, and steals usernames, passwords, session tokens, cookies, and browser reconnaissance data before exfiltrating it to C2 via HTTP POST.
A JavaScript Roundcube-focused stealer/backdoor that escapes the mail client's iFrame, steals usernames, passwords, two-factor authentication material, cookies, and browser reconnaissance data, then uses the session CSRF token to exploit a second Roundcube vulnerability to gain server-side foothold via webshell deployment or fallback payload delivery.
Plugin for the Scotch Android implant that adds advanced surveillance and post-exploitation capabilities including camera access, microphone recording, screenshots, notifications, and shell command execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.