Chinese hackers exploit WordPress, Zyxel flaws to steal government data in global campaign

Threat actor compromised nearly 1,000 network devices and stole over 18,500 records from government agencies

By LineZotpaper
Published
Read Time2 min
A Chinese-speaking hacking group linked to the Red Heron threat actor has exploited vulnerabilities in WordPress and Zyxel switches to steal sensitive data from government organizations worldwide, according to threat intelligence firm GreyNoise.

The campaign, active since June 2026, targeted multiple technologies but focused on two critical flaws. In WordPress, the attackers used the wp2shell vulnerabilities (CVE-2026-63030 and CVE-2026-60137) to breach at least 49 organizations in 29 countries. One intrusion at a Western government organization was particularly extensive, with the attacker spending 36 minutes conducting reconnaissance, attempting to bypass Microsoft Defender and AMSI, escalate privileges, and ultimately accessing a backend SQL server to steal 18,566 records containing plaintext passwords and personally identifiable information tied to law enforcement. The same actor also breached a Russian state organization in occupied Ukraine, which GreyNoise described as a “red-on-red” compromise.

In addition, on August 17, the actor began exploiting a high-severity flaw (CVE-2026-7273) in Zyxel GS1900 Smart Managed Switches, compromising 996 devices in 48 countries to extract device configurations, network information, and hashed root-level credentials. The actor also scanned for vulnerabilities in PAN-OS Global Protect, FlowiseAI, Nuclio, Proxmox, and Ubiquity. GreyNoise’s Global Observation Grid detected the activity, attributing the scans and attacks to the same IP address since early June.

§

Analysis

Why This Matters

  • The theft of government records containing plaintext passwords and PII poses a direct threat to national security and could enable further espionage or identity theft.
  • The scale of the campaign—996 compromised network devices and 49 organizations—highlights vulnerabilities in both web applications and network infrastructure.
  • The coordinated exploitation of multiple technologies suggests a sophisticated, resourceful adversary likely capable of sustained operations.

Background

Chinese state-linked hacking groups have long targeted government networks globally. The Red Heron group was previously linked to exploitation of critical flaws in Gitea, a self-hosted Git service. The wp2shell vulnerabilities in WordPress core were disclosed in mid-2026, with public exploits appearing in July, followed by rapid adoption by threat actors.

Key Perspectives

GreyNoise researchers: The campaign demonstrates methodical reconnaissance and credential theft, with the Western government intrusion showing a deliberate attempt to bypass security controls like AMSI and extract database credentials. Affected government agencies: They face the challenge of securing both common web platforms and network hardware, with stolen credentials potentially used in future attacks against connected systems. Cybersecurity community: The dual exploitation of WordPress and Zyxel flaws underscores the need for organizations to prioritise patching across diverse technology stacks, including network switches and content management systems.

What to Watch

  • Whether the stolen data is used in follow-on attacks or appears in file-sharing sites.
  • Exploitation of other technologies the actor scanned for, such as Proxmox and Ubiquity, especially if vulnerabilities are found.
  • Patch adoption rates for wp2shell and Zyxel CVE-2026-7273 across government and small business sectors.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.