Suspected Chinese threat actors have been caught breaking into university Roundcube mailservers, according to Proofpoint researchers. The campaign targeted a few dozen institutions, exploiting Roundcube webmail infrastructure to conduct espionage operations against academic targets.
Table of contents
It all starts with a generic phishing emailPRC-linked spies hid inside medical and military networks for more than a year, snooping through Gmail and stealing dataNotepad++ hijacking blamed on Chinese Lotus Blossom crew behind Chrysalis backdoorChinese spies used Maduro's capture as a lure to phish US govt agenciesChina's Ink Dragon hides out in European government networksMore links to PRC-backed spies48 Impressions