Chinese hackers have been exploiting vulnerabilities in popular technologies such as WordPress and ZyXEL switches to steal sensitive government data from thousands of devices worldwide. The hacking campaign, attributed to a threat actor linked to the Red Heron group, has compromised at least 49 organizations across 29 countries, with many more potentially affected.
The attackers targeted multiple systems, including PAN-OS Global Protect, FlowiseAI, Nuclio, Proxmox, Ubiquity, and others. They leveraged known security issues such as the wp2shell vulnerability in WordPress Core to breach backend databases, stealing over 18,500 records containing sensitive information. The hackers also exploited a high-severity flaw in ZyXEL GS1900 Smart Managed Switches to extract device configurations and network information.
GreyNoise, a threat intelligence company, detected the campaign through its Global Observation Grid (GOG) network of sensors. According to the researchers, the hacking activity originated from a single IP address and began in early June 2026. Public exploits for wp2shell became available mid-July, and active exploitation was observed just days later.
One notable intrusion occurred at an unnamed Western government organization, where the attacker used custom malware to perform extensive Windows and security reconnaissance. Over 36 minutes, the hackers tried 17 scripts to bypass security software, escalate privileges, create a local administrator account, and extract registry data. The attackers then used stolen credentials to access internal SQL servers, stealing sensitive records containing accounts, plaintext passwords, and personally identifiable information (PII).
The same attacker also breached a Russian state organization in occupied Ukraine, which the researchers described as a “red-on-red” compromise – where an adversary with conflicting interests manages to infiltrate another entity with similar goals. This highlights the potential for sophisticated attacks that can evade detection.
It’s worth noting that not all security issues leveraged in these attacks have been added to CISA’s catalog of Known Exploited Vulnerabilities (KEV). GreyNoise has provided a set of indicators of compromise (IoCs) connected to the observed activity, which include hashes for backdoors and command-and-control infrastructure.
In practical terms, this hacking campaign serves as a reminder that even with public exploits available, attackers can still achieve success by combining multiple vulnerabilities and exploiting human psychology. As such, it’s essential for organizations to prioritize security awareness training, patch management, and network monitoring to stay ahead of emerging threats.
Source: Bleeping Computer — 2026-09-22