SquareShell is a PHP webshell used to obtain remote code execution on compromised Roundcube mail servers. It has been observed in a targeted espionage campaign against universities in the United States and Canada, particularly organizations and departments associated with physics, engineering, astrophysics, particle physics, and national-security-related research. The activity has been tracked as UNK_MassTraction and assessed with low confidence as China-aligned based on infrastructure overlap, Chinese-language artifacts, and tradecraft consistent with prior Chinese intrusions into internet-facing mail systems.
In the observed intrusion chain, attackers first used phishing emails to trigger exploitation of Roundcube cross-site scripting vulnerability CVE-2024-42009 when a victim opened a crafted message in vulnerable webmail. After harvesting access through the associated credential-stealing stage, the operators attempted to exploit Roundcube deserialization vulnerability CVE-2025-49113 to gain server-side execution and write SquareShell to disk. Once deployed, SquareShell provided remote command execution on the mail server, enabling post-compromise control of the host. Reporting also indicates the webshell was timestomped to better blend into the environment, reflecting deliberate defense-evasion tradecraft.
SquareShell is best characterized as a server-side webshell used for post-exploitation on Linux-hosted PHP webmail infrastructure. In the same campaign, operators used VShell as a fallback implant when webshell deployment failed, suggesting SquareShell formed part of a broader toolchain for maintaining access and pivoting from exposed mail servers into internal networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
После сбора данных IceCube использует вспомогательные компоненты для эксплуатации критической уязвимости десериализации в Roundcube — CVE-2025-49113. С ее помощью атакующие пытаются установить PHP-веб-шелл SquareShell, который позволяет удаленно выполнять команды. | С ее помощью атакующие пытаются установить PHP-веб-шелл SquareShell, который позволяет удаленно выполнять команды.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
С ее помощью атакующие пытаются установить PHP-веб-шелл SquareShell, который позволяет удаленно выполнять команды.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
сам просмотр письма в уязвимой версии Roundcube запускает эксплуатацию старого XSS-бага CVE-2024-42009... После сбора данных IceCube использует вспомогательные компоненты для эксплуатации критической уязвимости десериализации в Roundcube — CVE-2025-49113.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PHP web shell used post-exploitation on compromised Roundcube servers to enable remote command execution.
A webshell installed after exploitation of Roundcube vulnerabilities to provide attacker access and enable remote code execution on compromised servers.
A PHP webshell with remote code execution capabilities used post-exploitation on compromised Roundcube servers.
A webshell installed on compromised Roundcube servers via CVE-2025-49113 to provide remote code execution and persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.