Cybersecurity and Privacy

Chinese-Speaking Threat Actor Exploits Zero-Days and Multi-Technology Vulnerabilities to Steal Global Government and Corporate Data

A highly sophisticated, Chinese-speaking cyberespionage campaign has come to light, revealing an extensive multi-vector assault targeting edge networking hardware, enterprise software, and backend databases. According to telemetry and threat intelligence gathered by GreyNoise through its Global Observation Grid (GOG) sensor network, the adversary has systematically exploited known and emerging vulnerabilities across platforms ranging from WordPress cores and ZyXEL switches to enterprise firewalls and container management systems. The primary objective of this malicious operation appears to be deep network reconnaissance, privilege escalation, and the large-scale extraction of sensitive personal identifiable information (PII), system configurations, and government records.

The ongoing campaign, which has been active since early June 2026, has been linked by researchers to a threat cluster associated with the Red Heron group—an adversary previously identified for exploiting critical code-injection vulnerabilities in self-hosted Git services like Gitea. Analysts tracking the infrastructure noted that scans and active intrusion attempts consistently originate from a unified set of source IP addresses, pointing to a centralized, highly coordinated operation designed to maximize geopolitical and commercial intelligence gathering.

Anatomy of the Intrusions: Multi-Vector Exploitation Strategy

Unlike targeted campaigns that rely on a single entry vector, this threat actor employs a diversified portfolio of exploits. By combining network edge device vulnerabilities with application-layer flaws, the group successfully breached organizations across at least 29 countries, heavily impacting small businesses, critical infrastructure, and government sectors.

Chinese hackers exploit WordPress, Zyxel flaws to steal govt data

The campaign’s broad scope relies on leveraging vulnerabilities across a wide array of prominent technologies, including PAN-OS GlobalProtect, FlowiseAI, Nuclio, Proxmox VE, Ubiquiti UniFi OS, and the Linux kernel. Rather than focusing on a single industry, the hackers have cast a wide net, utilizing automated scanning to identify vulnerable instances before deploying custom post-exploitation scripts tailored to each environment.

One notable highlight of the campaign’s expansive reach includes a "red-on-red" compromise involving the successful breach of a Russian state organization operating within occupied Ukrainian territory. However, the most alarming intelligence details a deeply methodical intrusion into an unnamed Western government agency, which serves as a textbook example of modern, hands-on-keyboard cyberespionage.

The Western Government Breach: A 36-Minute Masterclass in Evasion

The intrusion into the Western government organization began via the exploitation of critical "wp2shell" vulnerabilities in the WordPress Core component, tracked as CVE-2026-63030 and CVE-2026-60137. Publicly disclosed exploits for these flaws emerged in mid-July, with active exploitation observed in the wild merely days later.

Capitalizing on these remote code execution (RCE) flaws, the attacker established an initial foothold and immediately initiated an aggressive, 36-minute reconnaissance and lateral movement phase. Security logs analyzed by GreyNoise reveal a high degree of operational sophistication:

Chinese hackers exploit WordPress, Zyxel flaws to steal govt data
  • Security Posture Assessment: The threat actor actively queried the system to evaluate defensive measures, checking the status of Microsoft Defender, the Antimalware Scan Interface (AMSI), active listening ports, and local application restrictions.
  • Defense Evasion and Privilege Escalation: Over the course of the brief window, the adversary executed 17 distinct scripts specifically designed to bypass AMSI protections, perform token impersonation or theft, create rogue local administrator accounts, and extract sensitive registry data.
  • Database Harvesting: After mapping the internal network topology and uncovering hardcoded credentials for a backend database, the hackers launched a targeted password-spraying attack. This granted them unauthorized access to an internal Structured Query Language (SQL) server.

From this compromised database, the attackers exfiltrated at least 18,566 sensitive records. The harvested data contained critical assets, including user accounts, plaintext passwords, and highly sensitive personally identifiable information (PII) directly linked to government and law-enforcement personnel.

Expanding the Footprint: ZyXEL Switches and Ubiquiti Flaws

As the campaign progressed into late summer, the threat actor expanded their target profile beyond web applications to physical networking infrastructure. On August 17, the adversary initiated a mass-exploitation campaign targeting a high-severity security flaw (CVE-2026-7273) affecting ZyXEL GS1900 Smart Managed Switches. Within a short timeframe, the attackers successfully compromised 996 distinct devices spread across 48 countries, extracting critical network configuration files, topology maps, and hashed root-level credentials that could facilitate further lateral movement.

Simultaneously, the hackers attempted to chain a trio of critical vulnerabilities affecting Ubiquiti UniFi OS devices—tracked as CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910. These flaws, which allow unauthenticated remote code execution and root-level system takeover, have been under active exploitation globally since late June 2026, prompting urgent warnings from the Cybersecurity and Infrastructure Security Agency (CISA).

The threat actor’s expansive toolkit also incorporates exploits for several other major software components, including:

Chinese hackers exploit WordPress, Zyxel flaws to steal govt data
  • FlowiseAI (CVE-2026-56271)
  • Gitea Code Injection (CVE-2026-60004)
  • Nuclio Serverless Platform (CVE-2026-79756)
  • SENAITE LIMS (CVE-2026-54569)
  • Proxmox Virtual Environment (CVE-2023-54391)
  • Linux Kernel Dirty Pipe (CVE-2022-0847)

Security researchers have emphasized a concerning detail: several of the security issues leveraged extensively in this attack cluster have not yet been incorporated into CISA’s official catalog of Known Exploited Vulnerabilities (KEV), highlighting a dangerous gap between active threat intelligence and formal vulnerability tracking.

Chronology of the Threat Campaign

  • Early June 2026: GreyNoise sensors first record reconnaissance scans and targeted exploitation attempts originating from a consistent IP address infrastructure linked to the Red Heron-associated threat cluster.
  • Mid-June 2026: CISA flags multiple maximum-severity Ubiquiti UniFi OS flaws as actively exploited in the wild, laying the groundwork for widespread edge-device targeting.
  • Mid-July 2026: Public exploits for the WordPress Core wp2shell vulnerabilities (CVE-2026-63030 and CVE-2026-60137) become widely available, with active exploitation observed days later.
  • Late July to Early August 2026: The threat actor successfully breaches multiple organizations across 29 countries via WordPress vulnerabilities, culminating in the deep reconnaissance and data exfiltration attack on a Western government agency.
  • August 17, 2026: The campaign pivots to networking hardware, initiating mass exploitation of ZyXEL GS1900 Smart Managed Switches (CVE-2026-7273) across 48 countries.
  • September 2026: GreyNoise publishes comprehensive telemetry, attack timelines, and indicators of compromise (IoCs)—including backdoor hashes and command-and-control (C2) infrastructure details—to assist defenders in mitigating the campaign.

Industry Implications and Defensive Recommendations

The scale and complexity of this campaign underscore the evolving nature of modern cyber threats, where attackers seamlessly transition from enterprise web applications to edge routing hardware and database servers. By weaponizing a mix of zero-day vulnerabilities, newly disclosed software flaws, and aging unpatched bugs (such as Dirty Pipe), the adversary demonstrates a capability to adapt rapidly to the global vulnerability landscape.

Security analysts warn that organizations can no longer rely solely on perimeter defenses or perimeter patching cycles. The rapid weaponization of bugs like wp2shell and the Ubiquiti OS flaws demonstrates that the window between public disclosure and active exploitation has effectively closed, leaving defenders with hours—rather than weeks—to apply necessary patches.

In response to these findings, GreyNoise has released a comprehensive set of indicators of compromise (IoCs), encompassing cryptographic hashes of deployed backdoors and known command-and-control (C2) server addresses. Cybersecurity authorities strongly urge system administrators and IT security teams to audit their internet-facing assets, verify the patch status of all WordPress installations, ZyXEL switches, and Ubiquiti hardware, and implement rigorous multi-factor authentication and database monitoring to detect anomalous internal queries and password-spraying activities before data exfiltration can occur.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Device Kick
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.