Inside a China-linked university espionage campaign.
by Tim Leogrande, BSIT, MSCP, Ed.S.
🗓 JULY 16 2026 • 2 MIN READ
Proofpoint threat researchers reported last week that hackers with ties to China broke into the networks of American and Canadian colleges to steal confidential information and establish long-term access through web shells and backdoors.
These espionage-motivated breaches targeted engineering and physics departments, concentrating on professors and administrators with ties to national security, as well as groups studying particle physics and astrophysics.
Proofpoint identified fewer than ten victim universities and believes a few dozen may ultimately be impacted. The company first noticed the campaign in May and says it is still going strong, with a high probability that many victims have not yet been informed.
<aside> 💡
Researchers linked the attacks to two serious flaws in the open-source email software Roundcube, which were chained together to steal passwords and secure long-term access.
</aside>
The threat cluster, labeled UNK_MassTraction, used CVE-2024-42009 to run JavaScript in the victim's browser before gaining access to the mail server via CVE-2025-49113. The first exploit in the chain requires only that the victim open an email, so the attackers sent a series of generic lures to make that happen.
Proofpoint links the campaign to a Chinese threat actor group for three reasons:
Google threat hunters also just discovered a Chinese state-sponsored espionage cell that had spent years infiltrating systems and stealing data related to academia, medicine, the military, cybersecurity, and foreign policy.
In the past, China-linked attackers have focused on edge devices like routers and VPN concentrators, exploiting a variety of flaws to reach target networks without touching email servers. This campaign inverts that playbook. Instead of sending a message with a credential-harvesting URL or malware to attack an end user, it uses email to deploy an exploit chain against the mail server itself.
© 2026 Tim Leogrande. The opinions expressed herein are solely those of the author and do not necessarily reflect the views, policies, or positions of any affiliated organizations or individuals.