IceCube is a JavaScript-based credential-stealing payload used in espionage activity targeting vulnerable Roundcube webmail deployments. It has been associated with the China-aligned cluster tracked as UNK_MassTraction, which targeted universities in the United States and Canada, particularly physics, engineering, astrophysics, particle physics, and other research environments with potential national-security relevance. The malware is delivered after exploitation of the Roundcube cross-site scripting vulnerability CVE-2024-42009, typically when a victim opens a malicious email in a vulnerable webmail session.
IceCube is designed as a Roundcube-focused stealer operating in the victim’s browser. It escapes the application’s iframe context through DOM traversal, enabling access to the broader page DOM and the authenticated Roundcube session. Reported collection includes usernames, passwords, cookies, session tokens, two-factor authentication material, browser information, language settings, screen characteristics, and form field values. The malware also gathers environmental information for reconnaissance and transmits stolen data to attacker-controlled infrastructure.
Beyond credential and session theft, IceCube supports follow-on exploitation by abusing authenticated session context and anti-CSRF material to facilitate attempts against the Roundcube deserialization vulnerability CVE-2025-49113. In observed intrusions, this enabled progression from browser-side compromise toward server-side access, including deployment of webshell or backdoor tooling when exploitation succeeded. The broader campaign indicates that compromised mail servers were used as footholds for deeper network intrusion rather than solely for mailbox collection.
A separate historical use of the name IceCube appears in Android surveillance tooling as a plugin package for the Scotch implant within the MOONSHINE framework, where it provided capabilities such as camera access, audio recording, screenshots, notifications, and shell command execution. Because the same name has been used for distinct malware components in different ecosystems, the most widely recognized current usage in this context refers to the Roundcube-focused JavaScript stealer.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Proofpoint found that UNK_MassTraction used phishing emails containing malicious content designed to exploit CVE-2024-42009, a cross-site scripting (XSS) vulnerability in Roundcube. When executed in a vulnerable webmail client, the exploit allowed JavaScript to run in the victim's browser. | The JavaScript payload, tracked by Proofpoint as IceCube, was used to steal usernames, passwords, cookies and authentication data.
UNK_MassTraction exploited CVE-2024-42009 in Roundcube and used IceCube during post-exploitation, where the malware attempted to exploit CVE-2025-49113.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The JavaScript payload, tracked by Proofpoint as IceCube, was used to steal usernames, passwords, cookies and authentication data.
The IceCube.jar plugin package added further functionality: CAMERA: List available cameras and take pictures NOTIFICATION: Show a notification on the phone RECORD: Record audio from the microphone SCREEN_SNAP: Take screenshots SHELL: Execute a shell command
11 distinct techniques documented for this family, organized by ATT&CK tactic.
A suspected China-aligned threat cluster has been exploiting vulnerable Roundcube mail servers at universities in the US and Canada to steal credentials and establish network access.
IceCube 'is a fully-featured Roundcube stealer' that can harvest usernames, passwords, cookies, two-factor authentication (2FA) data, and browser information.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Post-exploitation malware used after Roundcube compromise; the malware also attempted to exploit CVE-2025-49113.
Stealer targeting Roundcube that steals usernames, passwords, cookies, two-factor authentication data, and browser information; it also uses auxiliary components to help exploit a Roundcube deserialization flaw for further compromise.
A fully featured Roundcube stealer that harvests usernames, passwords, cookies, two-factor authentication data, and browser information.
A stealer delivered through exploited Roundcube webmail sessions that escapes the Roundcube iFrame context, accesses the full DOM and authenticated session, and steals usernames, passwords, session tokens, cookies, and browser reconnaissance data before exfiltrating it to C2 via HTTP POST.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.