Chinese Hackers Exploit OwnCloud, WordPress Flaws to Steal Philippine Nuclear Data
Suspected Chinese-speaking threat actors have exploited known vulnerabilities to steal sensitive information from a Philippine nuclear research organization and a marine engineering company that provides services to the Philippine Navy.
Cybersecurity researchers at Hunt.io uncovered an exposed attacker-controlled server on August 13, 2026, containing custom exploit scripts, stolen documents, attack logs, and offensive tools.
The campaign highlights the growing cyber-espionage risks facing Philippine government, defense, scientific research, and critical infrastructure organizations amid heightened tensions in the South China Sea.
The attackers first targeted an internet-facing ownCloud server belonging to a Philippine nuclear research organization.
Chinese Hackers Exploit OwnCloud
Investigators linked the intrusion to CVE-2023-49105, a critical authentication-bypass vulnerability affecting vulnerable ownCloud installations configured with an empty pre-signed URL signing secret.
By exploiting the weakness, the operators were able to impersonate legitimate ownCloud users and access files without requiring their account passwords.
Hunt.io researchers identified five custom Python scripts used during the operation. The tools enabled attackers to download files through the ownCloud WebDAV interface while introducing randomized delays between requests.
Such delays may have been designed to make the malicious activity appear less automated and reduce the likelihood of detection by security monitoring systems. The attackers subsequently collected a broad range of highly sensitive nuclear research and organizational information.
The stolen material reportedly included nuclear-material account records, research-reactor core-component databases, radiation-safety documentation, operational manuals, strategic and information-technology plans, and employee records.
Investigators also discovered résumés, passport-related documents, foreign travel information, financial disclosure forms, and employee training materials.
Particularly concerning were credential-related files, including BitLocker recovery keys, a KeePass database, and AxCrypt-encrypted files, which could provide attackers with additional opportunities for access or lateral movement.
A recovered spreadsheet referenced approximately 9 GB of information allegedly stolen from the nuclear organization, indicating that the data found on the exposed attacker server may represent only a portion of the information collected during the intrusion.
The attackers also organized stolen files using folders containing Simplified Chinese names, including references to finance, radiation safety, nuclear-material accounts, and IT planning. Chinese-language comments, logs, and code documentation within the recovered scripts further suggested that the operator was likely a Chinese speaker.
Researchers also discovered a 192 MB database dump from ZKTeco BioTime, a personnel and attendance management platform.
The database reportedly contained information associated with Philippine science and research organizations. Such personnel information could potentially be used to identify employees, departments, access assignments, and individuals who may later become targets for phishing, social engineering, or additional intrusion attempts.
The same attacker infrastructure contained evidence of a separate compromise involving a Philippine marine engineering and shipbuilding company serving the Philippine Navy.
In this case, the operators exploited CVE-2024-28000, a privilege-escalation vulnerability in the LiteSpeed Cache WordPress plugin.
The flaw could allow attackers to generate a valid security hash, create an unauthorized administrator account, and gain control over a vulnerable WordPress website.
The attackers additionally deployed an XML-RPC password-brute-forcing script against the site’s administrator account.
According to Hunt.io, logs indicated that this technique successfully identified valid credentials, providing another route into the targeted environment.
The combination of vulnerability exploitation and credential attacks demonstrates how threat actors can use multiple techniques against organizations with internet-facing infrastructure.
The exposed server was associated with IP address 31.58.209[.]241, including port 8000 hosting an open directory containing tools, logs, and stolen information.
Investigators also identified port 8090 associated with a custom multi_backupd loader used to retrieve a second-stage payload.
Organizations operating ownCloud, WordPress, or other internet-facing applications should prioritize patching known vulnerabilities, enforcing multifactor authentication, monitoring administrative-account creation, reviewing unusual WebDAV and XML-RPC activity, and investigating unexpected outbound data transfers.
No Comment! Be the first one.