Chinese hackers have been exploiting vulnerabilities in WordPress and ZyXEL devices to steal sensitive government data on a massive scale. The attackers have breached at least 49 organizations in 29 countries, stealing over 18,500 records from backend databases. This brazen campaign highlights the importance of patching known security issues before they’re exploited by hackers.
The threat actor behind this attack is linked to the Red Heron group, which has been associated with exploiting critical flaws in various technologies. The attackers have been using exploits for known security issues, including a critical flaw in the Gitea self-hosted Git service. GreyNoise, a threat intelligence company, detected the activity through its Global Observation Grid (GOG) network of sensors.
The hackers targeted multiple technologies, including PAN-OS Global Protect, FlowiseAI, Nuclio, Proxmox, Ubiquity, and WordPress. They leveraged vulnerabilities in the WordPress Core component, known as wp2shell, to breach organizations worldwide. Public exploits for wp2shell became available in mid-July, and active exploitation was observed just a few days later. The campaign GreyNoise observed started around the same time, targeting high-value entities.
One of the most significant intrusions occurred at an unnamed Western government organization. The attacker used a custom wp2shell exploit and performed extensive Windows and security reconnaissance, checking Microsoft Defender, AMSI, available services, listening ports, local accounts, application restrictions, and database configuration. Over 36 minutes, the threat actor tried 17 scripts to bypass AMSI, escalate privileges through token impersonation or theft, create a local administrator, and extract registry data.
After locating credentials for a backend SQL database, the attackers used them in a password-spraying attack that gave them access to an internal SQL server. From there, they stole at least 18,566 records containing accounts, plaintext passwords, and personally identifiable information (PII) connected to government and law-enforcement agencies.
The same attacker also breached a Russian state organization in occupied Ukraine, which the researchers described as a “red-on-red” compromise. This highlights the threat actor’s willingness to target sensitive government data, regardless of the country or region.
In addition to exploiting WordPress vulnerabilities, the hackers targeted ZyXEL GS1900 Smart Managed Switches, compromising 996 devices in 48 countries. They attempted to chain Ubiquiti UniFi OS vulnerabilities (CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910) to obtain root-level remote code execution.
The CISA has flagged the three Ubiquiti flaws as actively exploited since late June 2026. GreyNoise also confirmed targeting of PAN-OS GlobalProtect, FlowiseAI (CVE-2026-56271), the Linux kernel’s Dirty Pipe flaw (CVE-2022-0847), Gitea (CVE-2026-60004), Nuclio (CVE-2026-79756), SENAITE LIMS (CVE-2026-54569) and Proxmox VE (CVE-2023-54391).
Not all security issues leveraged in attacks linked to this threat cluster have been added to CISA’s catalog of Known Exploited Vulnerabilities (KEV). GreyNoise has provided a set of indicators of compromise (IoCs) connected to the observed activity, which include hashes for backdoors and command-and-control (C2) infrastructure.
This campaign serves as a stark reminder that patching known security issues is crucial in preventing such attacks. Organizations must prioritize vulnerability management and stay up-to-date with the latest patches to avoid becoming victims of these types of exploits.
Source: Bleeping Computer — 2026-09-22