MIRAGE
Threat IntelligenceCVEs › CVE-2024-42009

CVE-2024-42009 — exposed on the internet

UNC1151 exploiting Roundcube to steal user credentials in a spearphishing campaign

Internet exposure observed by OffSeq scans · last 30 days

23
Exposed hosts
9.3
CVSS
79.6%
EPSS

Found on 23 internet-exposed hosts by OffSeq scans; no in-the-wild exploitation has been observed against OffSeq honeypots in this window.

About CVE-2024-42009

The UNC1151 threat actor is exploiting a critical vulnerability (CVE-2024-42009) in the Roundcube webmail client through a spearphishing campaign targeting primarily Polish organizations. Malicious JavaScript embedded in phishing emails installs a stealthy Service Worker in victims' browsers upon simply opening the email, intercepting login credentials and exfiltrating them to attacker-controlled infrastructure without further user interaction. A second vulnerability (CVE-2025-49113) may be chained to increase persistence and impact. Stolen credentials enable attackers to access mailboxes, harvest address books, and propagate phishing internally, facilitating lateral movement. The attack bypasses many traditional endpoint defenses and is difficult to detect due to the abuse of browser Service Workers. The campaign also threatens neighboring Central European countries with significant Roundcube deployments. Organizations are urged to patch vulnerabilities, monitor for unusual Service Worker activity, enforce multi-factor authentication, and enhance email filtering to mitigate risks.

OffSeq internet scanning found CVE-2024-42009 on 23 exposed hosts in the last 30 days. OffSeq honeypots have not recorded in-the-wild exploitation of this CVE in the current window — this page tracks its exposure footprint and status; if exploitation begins, the live honeypot signal will appear here.

Exposed-host countries

Exposed via

roundcube

Open the live CVE-2024-42009 view →

References