Chinese-Speaking Hackers Exploit WordPress, ZyXEL and Ubiquiti Flaws to Steal Government Data
A Chinese-speaking threat actor exploited vulnerabilities in WordPress and ZyXEL GS1900 smart managed switches to compromise 996 devices and steal more than 18,500 records from backend databases.
The attackers also targeted PAN-OS GlobalProtect, FlowiseAI, Nuclio, Proxmox, Ubiquiti and other technologies by exploiting known security flaws.
GreyNoise researchers said the scans and attacks originated from the same IP address. The activity has been observed since early June 2026 and is believed to be linked to threat actors associated with the Red Heron group, which has also been connected to exploitation of a critical vulnerability in the self-hosted Gitea Git service.
The activity was identified by threat intelligence firm GreyNoise through its Global Observation Grid (GOG) sensor network.
WordPress exploit used to target 49 organizations
According to researchers, the attackers used vulnerabilities in the wp2shell WordPress Core component, tracked as CVE-2026-63030 and CVE-2026-60137, to compromise at least 49 organizations in 29 countries.
A public exploit for wp2shell became available in mid-July, with active exploitation observed several days later. The campaigns monitored by GreyNoise began around the same time and focused on high-value organizations.
Most targets were small businesses and government entities, although anonymous Western government organizations were among the most prominent targets.
The attackers used a custom wp2shell exploit to conduct extensive Windows and security reconnaissance. Their checks included Microsoft Defender, Antimalware Scan Interface (AMSI), available services, listening ports, local accounts, application restrictions and database configurations.
Over a 36-minute period, the attackers attempted to run 17 scripts designed to bypass AMSI, escalate privileges by impersonating or stealing tokens, create local administrator accounts and extract registry data, GreyNoise said.
After discovering credentials for a backend SQL database, the attackers used them in a password-spraying attack to access an internal SQL server. They then stole at least 18,566 records.
The stolen data included government- and law-enforcement-related accounts, plaintext passwords and personally identifiable information (PII), according to the researchers.

Source: GreyNoise
The same attackers also infiltrated Russian state organizations in occupied Ukraine, in what researchers described as a “red-on-red” compromise.
Attackers exploit ZyXEL, Ubiquiti and other vulnerabilities
On August 17, the attackers began exploiting a high-severity vulnerability in the ZyXEL GS1900 Smart Managed Switch. The flaw, tracked as CVE-2026-7273, was used to compromise 996 devices across 48 countries.
The attackers extracted device configurations, network information and hashed root-level credentials from the compromised ZyXEL switches.
.jpg)
Source: GreyNoise
The hackers also attempted to achieve root-level remote code execution by chaining three vulnerabilities in Ubiquiti UniFi OS: CVE-2026-34908, CVE-2026-34909 and CVE-2026-34910.
CISA reported that the three Ubiquiti flaws had been actively exploited since late June 2026.
GreyNoise also observed the threat actors targeting:
- PAN-OS GlobalProtect
- FlowiseAI, including CVE-2026-56271
- The Linux kernel Dirty Pipe vulnerability, CVE-2022-0847
- Gitea, including CVE-2026-60004
- Nuclio, including CVE-2026-79756
- SENAITE LIMS, including CVE-2026-54569
- Proxmox VE, including CVE-2023-54391
The researchers emphasized that not every vulnerability exploited by the threat cluster has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog.
GreyNoise published indicators of compromise (IoCs) associated with the activity, including backdoors, command-and-control (C2) infrastructure and relevant hashes.
Join Mikko Hypponen and security leaders from the NFL, Chanel and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix and revalidate at machine speed.
Source: www.bleepingcomputer.com



