The campaign, active since June 2026, targeted multiple technologies but focused on two critical flaws. In WordPress, the attackers used the wp2shell vulnerabilities (CVE-2026-63030 and CVE-2026-60137) to breach at least 49 organizations in 29 countries. One intrusion at a Western government organization was particularly extensive, with the attacker spending 36 minutes conducting reconnaissance, attempting to bypass Microsoft Defender and AMSI, escalate privileges, and ultimately accessing a backend SQL server to steal 18,566 records containing plaintext passwords and personally identifiable information tied to law enforcement. The same actor also breached a Russian state organization in occupied Ukraine, which GreyNoise described as a “red-on-red” compromise.
In addition, on August 17, the actor began exploiting a high-severity flaw (CVE-2026-7273) in Zyxel GS1900 Smart Managed Switches, compromising 996 devices in 48 countries to extract device configurations, network information, and hashed root-level credentials. The actor also scanned for vulnerabilities in PAN-OS Global Protect, FlowiseAI, Nuclio, Proxmox, and Ubiquity. GreyNoise’s Global Observation Grid detected the activity, attributing the scans and attacks to the same IP address since early June.