A webmail inbox is becoming the entry point to the mail server itself, and that breaks the usual assumption that this is just a mailbox problem. In this campaign, opening a malicious Roundcube message can hand over browser-stored credentials and session material, then use that access to plant a webshell and keep coming back after the first message is gone.
Proofpoint says UNK_MassTraction has been chaining two patched Roundcube flaws against U.S. and Canadian university physics and engineering departments since May, with fewer than 10 victims identified so far and more possibly affected. The activity has targeted administrators and professors, used generic lures and compromised or spoofed senders, and is aimed at long-lived mail-server access rather than simple mailbox theft.
Even if the original phishing email is removed and passwords are reset, stolen session data can keep the foothold alive.