Chinese hackers exploit WordPress, Zyxel flaws to steal govt data

A sophisticated, state-sponsored cyber espionage group, believed to originate from China, has been observed conducting an extensive campaign exploiting a diverse array of software and hardware vulnerabilities, including critical flaws in WordPress and Zyxel network devices. This multifaceted operation has led to the compromise of hundreds of networked devices and the exfiltration of thousands of sensitive records, including government and law enforcement data, across dozens of countries. The attackers’ strategic selection of targets and their adeptness at weaponizing both recently discovered and established security vulnerabilities underscore a highly capable and persistent threat to global digital security.

The intelligence, gathered through a global network of sensors, indicates that this Chinese-speaking adversary has systematically targeted a wide spectrum of technologies, ranging from popular content management systems to enterprise-grade networking equipment and specialized IT infrastructure. This broad approach suggests an objective beyond mere opportunistic exploitation, pointing towards a deliberate and sustained effort to gather intelligence and maintain persistent access within high-value networks worldwide. The campaign’s observed activities, which began as early as June 2026, have been linked to an entity associated with the "Red Heron" group, an advanced persistent threat (APT) actor previously implicated in exploiting a critical vulnerability within the Gitea self-hosted Git service. This connection highlights a pattern of leveraging critical code injection and remote execution flaws to establish initial footholds.

Central to this extensive campaign was the exploitation of two critical vulnerabilities within the WordPress Core component, collectively referred to as "wp2shell" (CVE-2026-63030 and CVE-2026-60137). These remote code execution (RCE) flaws, for which public exploits became available in mid-July 2026, were quickly weaponized by the adversary. The speed with which the group integrated these vulnerabilities into their attack arsenal demonstrates a high level of agility and a proactive approach to vulnerability intelligence. The campaign saw the successful breach of at least 49 organizations across 29 nations, with a particular emphasis on small businesses and government entities, indicating a strategic preference for targets that may possess valuable data but potentially have less robust cybersecurity defenses compared to larger enterprises.

One incident, involving an undisclosed Western government organization, stands out as a prime example of the attacker’s methodical approach. Following the initial compromise via a custom wp2shell exploit, the threat actors initiated an exhaustive reconnaissance phase within the compromised Windows environment. This involved meticulous scrutiny of the target system’s security posture, including checks for Microsoft Defender, Anti-Malware Scan Interface (AMSI) status, active services, listening ports, local user accounts, application restrictions, and intricate database configurations. Over a concentrated period of 36 minutes, the adversary deployed no fewer than 17 distinct scripts. These scripts were designed for a variety of malicious purposes, including bypassing AMSI defenses, escalating privileges through sophisticated techniques like token impersonation or theft, establishing new local administrator accounts for persistent access, and systematically extracting critical registry data.

Chinese hackers exploit WordPress, Zyxel flaws to steal govt data

The culmination of this internal reconnaissance led to the discovery of credentials for a backend SQL database. These credentials were then immediately weaponized in a targeted password-spraying attack, granting the attackers unauthorized access to an internal SQL server. From this pivotal point, the threat actors successfully exfiltrated a staggering 18,566 records. The stolen data was found to contain highly sensitive information, including user accounts, plaintext passwords, and personally identifiable information (PII) directly linked to government and law enforcement agencies. The compromise of such data poses significant risks, not only for the individuals whose information was exposed but also for national security, potentially enabling further espionage, blackmail, or disruption activities.

Further illustrating the geopolitical complexities of cyber warfare, the same threat actor was also responsible for compromising a Russian state organization operating within occupied Ukrainian territory. This particular incident has been characterized by threat intelligence experts as a "red-on-red" compromise, a term used to describe cyberattacks between adversaries who might otherwise be considered aligned or opposed to a common third party. Such an event underscores the fluid and often opportunistic nature of state-sponsored cyber operations, where strategic objectives can transcend traditional geopolitical alignments in the pursuit of intelligence or operational advantage.

Beyond WordPress, the adversary demonstrated a broad technical capability by exploiting vulnerabilities in a range of other critical systems. On August 17, 2026, the group initiated a widespread attack leveraging a high-severity flaw (CVE-2026-7273) in ZyXEL GS1900 Smart Managed Switches. This exploitation resulted in the compromise of 996 devices across 48 countries, allowing the attackers to extract crucial device configurations, detailed network information, and hashed root-level credentials. The compromise of network switches is particularly alarming, as these devices form the backbone of network infrastructure, offering attackers unparalleled visibility and control over network traffic, enabling deep-seated espionage or potential sabotage.

In addition to these direct compromises, the hackers actively attempted to chain multiple vulnerabilities within Ubiquiti UniFi OS, specifically CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910. These flaws are known to collectively allow for unauthenticated root-level remote code execution, granting attackers complete control over affected UniFi devices. The Cybersecurity and Infrastructure Security Agency (CISA) had previously flagged these three Ubiquiti vulnerabilities as actively exploited since late June 2026, underscoring the urgency of patching and the severe risk posed by unaddressed weaknesses in widely deployed network management systems.

Chinese hackers exploit WordPress, Zyxel flaws to steal govt data

The scope of this campaign further extended to targeting other prominent technologies, including PAN-OS GlobalProtect, a widely used VPN solution; FlowiseAI (CVE-2026-56271), an AI workflow automation platform; Nuclio (CVE-2026-79756), a serverless platform; SENAITE LIMS (CVE-2026-54569), a laboratory information management system; and Proxmox VE (CVE-2023-54391), a virtualization management platform. The group also capitalized on the notorious Linux kernel "Dirty Pipe" flaw (CVE-2022-0847) and the Gitea vulnerability (CVE-2026-60004), demonstrating a versatile toolkit capable of attacking diverse operating systems and application stacks. The consistent targeting of critical infrastructure components, development platforms, and data management systems across such a wide array of vendors and technologies paints a clear picture of a well-resourced and strategic adversary aiming for deep and persistent access into sensitive networks.

A concerning observation from this campaign is that not all the security issues actively leveraged by this threat cluster have yet been formally added to CISA’s catalog of Known Exploited Vulnerabilities (KEV). This gap highlights a challenge for defenders, as the absence of a KEV listing might lead organizations to underestimate the immediate threat posed by certain vulnerabilities, delaying critical patching efforts. The rapid exploitation of newly disclosed vulnerabilities, coupled with the targeting of long-standing, unpatched flaws, underscores the continuous cat-and-mouse game between sophisticated attackers and cybersecurity defenders.

The strategic motivations behind this broad-spectrum targeting are likely multifaceted. The acquisition of government data, especially plaintext passwords and PII from law enforcement, provides invaluable intelligence for espionage, identifying targets for future social engineering attacks, or even compromising agents and sources. The control gained over network infrastructure devices like Zyxel switches and Ubiquiti UniFi systems offers persistent access, enabling passive data collection, traffic manipulation, and potentially the deployment of further malicious payloads for long-term intelligence gathering. The targeting of AI platforms and development environments could be indicative of an interest in intellectual property theft or gaining insights into advanced technological capabilities.

For organizations, the implications are profound. The sheer breadth of technologies targeted means that no single defense strategy is sufficient. A holistic approach is required, encompassing rigorous vulnerability management, continuous threat intelligence monitoring, robust network segmentation, and strong authentication mechanisms. Given the adversary’s proven capability to bypass security controls and escalate privileges, proactive threat hunting and rapid incident response capabilities are paramount. The consistent use of known exploits, even those dating back years, serves as a stark reminder of the critical importance of timely patching and configuration management. Furthermore, the "red-on-red" compromise scenario emphasizes that geopolitical alliances do not guarantee immunity from cyberattacks, and organizations must maintain vigilance regardless of their perceived political alignment.

Chinese hackers exploit WordPress, Zyxel flaws to steal govt data

As the digital landscape continues to evolve, characterized by increasing connectivity and the integration of AI into critical processes, the challenge of defending against such sophisticated state-sponsored actors will only grow. This campaign serves as a critical intelligence brief, underscoring the necessity for governments and private sector entities alike to invest significantly in advanced cybersecurity defenses, foster greater information sharing, and develop proactive strategies to anticipate and neutralize emerging threats from highly capable cyber espionage units. The ongoing exploitation of both novel and established vulnerabilities by persistent threat actors like the one associated with "Red Heron" represents a significant and enduring risk to national security and global digital trust.

Related Posts

Urgent Directive Issued as CISA Flags Actively Exploited Critical Linux Kernel Vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-priority alert, warning organizations about the immediate and active exploitation of three distinct vulnerabilities within the Linux kernel, one…

Cloud Commerce Platform BigCommerce Grapples with Supply Chain Breach Via Compromised Third-Party Application Credentials

Leading cloud-based e-commerce provider BigCommerce has initiated notifications to numerous merchants regarding a significant data incident stemming from the compromise of credentials associated with Ribon, a third-party application, which attackers…

Leave a Reply

Your email address will not be published. Required fields are marked *