CVE-2024-42009 — exposed on the internet
UNC1151 exploiting Roundcube to steal user credentials in a spearphishing campaign
Internet exposure observed by OffSeq scans · last 30 days
Found on 27 internet-exposed hosts by OffSeq scans; no in-the-wild exploitation has been observed against OffSeq honeypots in this window.
About CVE-2024-42009
The UNC1151 threat actor is exploiting a critical vulnerability (CVE-2024-42009) in the Roundcube webmail client through a spearphishing campaign targeting primarily Polish organizations. Malicious JavaScript embedded in phishing emails installs a stealthy Service Worker in victims' browsers upon simply opening the email, intercepting login credentials and exfiltrating them to attacker-controlled infrastructure without further user interaction. A second vulnerability (CVE-2025-49113) may be chained to increase persistence and impact. Stolen credentials enable attackers to access mailboxes, harvest address books, and propagate phishing internally, facilitating lateral movement. The attack bypasses many traditional endpoint defenses and is difficult to detect due to the abuse of browser Service Workers. The campaign also threatens neighboring Central European countries with significant Roundcube deployments. Organizations are urged to patch vulnerabilities, monitor for unusual Service Worker activity, enforce multi-factor authentication, and enhance email filtering to mitigate risks.
OffSeq internet scanning found CVE-2024-42009 on 27 exposed hosts in the last 30 days. OffSeq honeypots have not recorded in-the-wild exploitation of this CVE in the current window — this page tracks its exposure footprint and status; if exploitation begins, the live honeypot signal will appear here.
Open the live CVE-2024-42009 view →