Cybersecurity

Hacking Campaign Exploits WordPress and Zyxel Vulnerabilities to Steal Government Data

GreyNoise detected a campaign conducted by a Chinese-speaking threat actor that exploited vulnerabilities in WordPress and a wide range of technologies, compromising 49 organizations in 29 countries and 996 devices, and stealing 18,566 records from an SQL server belonging to a Western government entity.

2026-09-22
3 min read
0 views
certi.news Editorial Team
Hacking Campaign Exploits WordPress and Zyxel Vulnerabilities to Steal Government Data

Threat intelligence company GreyNoise detected a multistage attack campaign in which a Chinese-speaking threat actor exploited vulnerabilities in WordPress, Zyxel switches, and other technology components to access sensitive data. The company’s findings indicate that at least 49 organizations in 29 countries were compromised, in addition to 996 devices in 48 countries.

Scanning and attack operations began from approximately a single IP address in early June 2026, and GreyNoise linked the activity to a threat actor associated with the Red Heron group, which had previously been linked to the exploitation of a critical vulnerability in self-hosted Gitea. The company discovered the campaign through its Global Observation Grid sensor network.

Stealing Data from a Government Entity

The attacker exploited the two wp2shell vulnerabilities, CVE-2026-63030 and CVE-2026-60137, in the WordPress Core component. After compromising an unnamed Western government organization, the attacker conducted extensive reconnaissance of the Windows environment and security mechanisms, including Microsoft Defender, AMSI, services, open ports, local accounts, application restrictions, and database configurations.

Within 36 minutes, the attacker ran 17 scripts to attempt to bypass AMSI, escalate privileges by impersonating or stealing tokens, create a local administrator account, and extract data from the Windows Registry. After finding credentials for a backend SQL database, the attacker used them in a password-spraying attack to access an internal SQL server, from which at least 18,566 records were stolen.

The records included plaintext accounts and passwords and personally identifiable information associated with government entities and law enforcement agencies. The attacker also compromised a Russian government organization in territories occupied in Ukraine, in an incident that researchers described as a “red-on-red” compromise.

Targeting Network Switches and Multiple Platforms

On August 17, the actor began exploiting the high-severity vulnerability CVE-2026-7273 in Zyxel GS1900 Smart Managed Switches, compromising 996 devices in 48 countries to extract device configurations, network information, and root credentials after hashing.

The attackers also attempted to chain three vulnerabilities in Ubiquiti UniFi OS—CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910—to achieve remote command execution with root privileges. CISA had classified these vulnerabilities among those actively exploited since late June.

What Matters to Defense Teams?

GreyNoise confirmed the targeting of PAN-OS GlobalProtect and FlowiseAI through CVE-2026-56271, the Dirty Pipe vulnerability in the Linux kernel, and Gitea through CVE-2026-60004, in addition to Nuclio, SENAITE LIMS, and Proxmox VE. In practice, the campaign highlights the danger of treating each exposed service in isolation; the attacker moved from a web application to Windows systems, databases, and network equipment, taking advantage of credentials discovered within the environment.

The absence of a vulnerability from CISA’s Known Exploited Vulnerabilities Catalog does not mean that it is not being exploited in practice, as GreyNoise noted that some of the issues used in this campaign had not been added to the catalog. The company provided indicators of compromise, including hashes for backdoors and command-and-control infrastructure, enabling security teams to compare their logs with these indicators and verify whether similar activity is present.

News source
BleepingComputer
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news