{"id":7829,"date":"2026-09-22T21:05:19","date_gmt":"2026-09-22T21:05:19","guid":{"rendered":"https:\/\/lockitsoft.com\/?p=7829"},"modified":"2026-09-22T21:05:19","modified_gmt":"2026-09-22T21:05:19","slug":"chinese-hackers-exploit-multiple-technologies-to-steal-government-data-and-sensitive-records","status":"publish","type":"post","link":"https:\/\/lockitsoft.com\/?p=7829","title":{"rendered":"Chinese Hackers Exploit Multiple Technologies to Steal Government Data and Sensitive Records"},"content":{"rendered":"<p>A sophisticated Chinese-speaking threat actor has been actively exploiting a diverse array of vulnerabilities across enterprise network hardware and content management systems, successfully infiltrating nearly a thousand devices and siphoning thousands of sensitive government records. According to findings published by threat intelligence firm GreyNoise, the campaign leverages zero-day and known exploits targeting platforms ranging from ZyXEL switches to WordPress cores, highlighting a worrying trend of multi-vector cyber espionage aimed at high-value entities. <\/p>\n<p>The campaign, tracked since early June, has been tentatively linked by researchers to an adversary cluster associated with the Red Heron group\u2014a threat actor previously identified by cybersecurity analysts for exploiting critical flaws in self-hosted Git services like Gitea. Security telemetry gathered through the GreyNoise Global Observation Grid (GOG) sensor network indicates that scanning activity and targeted intrusions consistently originate from identical infrastructure, suggesting a centralized, methodical operation designed to harvest intelligence from public sector and small-to-medium business environments globally.<\/p>\n<p>An Anatomy of a Multi-Vector Intrusion Campaign<\/p>\n<p>The operational scope of the campaign is notable for its breadth. Rather than focusing on a single software ecosystem, the threat actor has cast a wide net, systematically targeting vulnerabilities across PAN-OS GlobalProtect, FlowiseAI, Nuclio, Proxmox, Ubiquiti UniFi OS, and various Linux kernel mechanisms. However, the most destructive breaches analyzed by researchers stemmed from weaponized flaws in WordPress and ZyXEL networking hardware.<\/p>\n<p>In mid-July, public exploits emerged for the critical &quot;wp2shell&quot; vulnerabilities affecting the WordPress Core component, tracked as CVE-2026-63030 and CVE-2026-60137. Within days, active exploitation of these remote code execution (RCE) flaws was recorded globally. The GreyNoise researchers observed the threat actor leveraging these exact vectors to breach at least 49 organizations spanning 29 countries. While the victim pool included numerous small businesses and local enterprises, the attackers also successfully compromised high-profile government entities.<\/p>\n<figure class=\"article-inline-figure\"><img decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/content\/hl-images\/2025\/03\/05\/chinese-hacker-flag.jpg\" alt=\"Chinese hackers exploit WordPress, Zyxel flaws to steal govt data\" class=\"article-inline-img\" loading=\"lazy\" \/><\/figure>\n<p>Detailing a Targeted Western Government Infiltration<\/p>\n<p>A particularly illustrative intrusion documented by GreyNoise involved an unnamed Western government organization. Upon gaining initial access via a custom wp2shell exploit, the adversary did not immediately deploy ransomware or disrupt operations. Instead, they executed a calculated, 36-minute reconnaissance phase designed to map the internal architecture and evade defensive tooling.<\/p>\n<p>During this brief window, the attackers tested 17 distinct scripts aimed at bypassing the Anti-Malware Scan Interface (AMSI), neutralizing Microsoft Defender mechanisms, evaluating active services, identifying listening ports, inspecting local user accounts, and checking application restrictions. Utilizing advanced tactics, they attempted privilege escalation via token impersonation and theft, sought to create a persistent local administrator account, and systematically extracted sensitive registry data.<\/p>\n<p>Once foundational access was established, the hackers pivoted toward internal databases. After discovering credentials for a backend SQL server, they launched a password-spraying attack that successfully granted them entry. From this internal repository, the adversary exfiltrated over 18,500 records. Analysis of the stolen data revealed a trove of sensitive information, including user accounts, plaintext passwords, and personally identifiable information (PII) directly tied to government personnel and law enforcement agencies. <\/p>\n<p>In a bizarre geopolitical twist characteristic of modern cyber warfare, the same threat actor also breached a Russian state organization operating within occupied Ukrainian territory\u2014an incident researchers categorized as a &quot;red-on-red&quot; compromise, underscoring the relentless, intelligence-agnostic nature of the campaign.<\/p>\n<p>Chronology of Exploitation: From ZyXEL Switches to Ubiquiti Infrastructure<\/p>\n<figure class=\"article-inline-figure\"><img decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2026\/September\/steps.jpg\" alt=\"Chinese hackers exploit WordPress, Zyxel flaws to steal govt data\" class=\"article-inline-img\" loading=\"lazy\" \/><\/figure>\n<p>The threat actor&#8217;s offensive operations demonstrated continuous evolution throughout the summer months, expanding from web content management systems to core networking hardware.<\/p>\n<p>On August 17, the adversary broadened their tactical arsenal by targeting a high-severity security flaw, designated as CVE-2026-7273, within ZyXEL GS1900 Smart Managed Switches. By exploiting this vulnerability, the hackers successfully compromised 996 distinct devices spread across 48 countries. The objective here was primarily informational: extracting device configurations, network topology maps, and hashed root-level credentials to facilitate lateral movement across enterprise networks.<\/p>\n<p>Simultaneously, the threat actor attempted to chain multiple critical vulnerabilities affecting Ubiquiti UniFi OS devices\u2014specifically CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910. These flaws, which allow unauthenticated attackers to achieve root-level remote code execution, have been a focal point for malicious actors since late June, prompting urgent warnings from the Cybersecurity and Infrastructure Security Agency (CISA).<\/p>\n<p>Beyond hardware appliances, GreyNoise confirmed active targeting of several other major software vulnerabilities. These included FlowiseAI (CVE-2026-56271), the notorious Linux kernel &quot;Dirty Pipe&quot; privilege escalation flaw (CVE-2022-0847), Gitea code injection vulnerabilities (CVE-2026-60004), Nuclio serverless platform issues (CVE-2026-79756), SENAITE LIMS laboratory information management system bugs (CVE-2026-54569), and Proxmox VE virtualization platform flaws (CVE-2023-54391).<\/p>\n<p>Implications and the Gap in Official Vulnerability Catalogs<\/p>\n<p>The findings released by GreyNoise carry significant implications for enterprise security teams and national cybersecurity agencies alike. Notably, researchers emphasized that several of the security issues leveraged by this specific threat cluster have not yet been formally incorporated into CISA\u2019s official catalog of Known Exploited Vulnerabilities (KEV). This lag between active exploitation in the wild and formal cataloging creates a dangerous blind spot for organizations that rely strictly on KEV lists to prioritize patching schedules.<\/p>\n<figure class=\"article-inline-figure\"><img decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2026\/September\/timeline(2).jpg\" alt=\"Chinese hackers exploit WordPress, Zyxel flaws to steal govt data\" class=\"article-inline-img\" loading=\"lazy\" \/><\/figure>\n<p>The campaign illustrates the shifting methodologies of modern state-sponsored and economically motivated espionage groups. Rather than relying on sophisticated, custom-built malware for every phase of an attack, threat actors increasingly utilize &quot;living off the land&quot; techniques combined with rapidly weaponized public exploits for known vulnerabilities. By chaining multiple flaws across disparate technologies\u2014from edge routers and smart switches to backend databases and content management systems\u2014attackers can pierce perimeter defenses with minimal friction.<\/p>\n<p>Official Responses and Mitigation Guidance<\/p>\n<p>In response to the escalating threat landscape, cybersecurity authorities and intelligence firms have urged organizations to audit their external attack surfaces immediately. System administrators managing ZyXEL Smart Managed Switches, Ubiquiti infrastructure, and WordPress instances are advised to apply the latest security patches without delay. <\/p>\n<p>GreyNoise has published comprehensive indicators of compromise (IoCs) associated with the Red Heron-linked cluster, including file hashes for deployed backdoors and known command-and-control (C2) server IP addresses. Organizations are encouraged to cross-reference their network logs against these IoCs to detect potential historical intrusions. <\/p>\n<p>As digital infrastructure becomes increasingly interconnected, the events of this campaign serve as a stark reminder that legacy unpatched devices, forgotten staging servers, and peripheral network hardware remain open invitations for persistent threat actors seeking deep, unobserved access to critical government and corporate networks.<\/p>\n<!-- RatingBintangAjaib -->","protected":false},"excerpt":{"rendered":"<p>A sophisticated Chinese-speaking threat actor has been actively exploiting a diverse array of vulnerabilities across enterprise network hardware and content management systems, successfully infiltrating nearly a thousand devices and siphoning thousands of sensitive government records. According to findings published by threat intelligence firm GreyNoise, the campaign leverages zero-day and known exploits targeting platforms ranging from &hellip;<\/p>\n","protected":false},"author":25,"featured_media":7828,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[108],"tags":[30,109,352,76,1746,75,4443,111,1412,110,1384,4444,2885],"class_list":["post-7829","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-protection","tag-chinese","tag-cybersecurity","tag-data","tag-exploit","tag-government","tag-hackers","tag-multiple","tag-privacy","tag-records","tag-security","tag-sensitive","tag-steal","tag-technologies"],"_links":{"self":[{"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/posts\/7829","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/users\/25"}],"replies":[{"embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=7829"}],"version-history":[{"count":0,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/posts\/7829\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/media\/7828"}],"wp:attachment":[{"href":"https:\/\/lockitsoft.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=7829"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=7829"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=7829"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}