SquareShell is a PHP webshell used to obtain remote code execution on compromised Roundcube webmail servers. It has been observed in intrusion activity attributed with low confidence to the China-aligned espionage cluster UNK_MassTraction, which targeted universities in the United States and Canada, particularly physics, engineering, astrophysics, particle physics, and other research areas with national security relevance. In the observed attack chain, operators first used phishing emails to trigger exploitation of Roundcube vulnerabilities and then leveraged the deserialization flaw CVE-2025-49113 to install SquareShell on the mail server. Once deployed, the webshell provided server-side command execution and a durable foothold for follow-on operations. Reported tradecraft around its deployment included attempts to blend into the environment by masquerading as a legitimate Roundcube component and timestomping the implanted file. SquareShell functioned as a post-compromise access mechanism enabling continued control of the server and further intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attackers then use a deserialization exploit, CVE-2025-49113, to install a webshell called SquareShell and a VShell implant, enabling remote code execution.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The attackers then use a deserialization exploit, CVE-2025-49113, to install a webshell called SquareShell and a VShell implant, enabling remote code execution.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A webshell installed after exploitation of Roundcube vulnerabilities to provide attacker access and enable remote code execution on compromised servers.
A PHP webshell with remote code execution capabilities used post-exploitation on compromised Roundcube servers.
A webshell installed on compromised Roundcube servers via CVE-2025-49113 to provide remote code execution and persistence.
A simple PHP webshell written to disk through exploitation of Roundcube deserialization, timestomped to blend in, and capable of remote code execution via multiple PHP execution functions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.