ProBackend
ai wordpress plugin supply chain threats
2 hours ago4 min read

Chinese Hackers Leverage ZyXEL Switches and WordPress to Infiltrate Government Systems

A Chinese-speaking threat actor exploits ZyXEL GS1900 switches and WordPress vulnerabilities to steal government data. What the campaign means for defenders.

Introduction

A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive government data, as reported by BleepingComputer (Source: https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/). The campaign, detected by GreyNoise through its Global Observation Grid, has compromised hundreds of devices and exfiltrated over 18,500 records containing accounts, passwords, and personally identifiable information linked to government and law‑enforcement agencies.

Threat Actor Overview

The adversary, attributed to a group linked to the Red Heron family, began targeting high‑value entities in early June 2026 and intensified activity after public exploits for the wp2shell vulnerability became available in mid‑July (Source: https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/). Researchers observed scans and attacks originating from a consistent IP address, indicating a coordinated effort. The group leverages a mix of zero‑day and publicly known flaws across multiple platforms to achieve initial access and maintain persistence.

Exploitation of WordPress

The core of the attack chain involves the wp2shell backdoor in WordPress Core, identified as CVE‑2026‑63030 and CVE‑2026‑60137 (Source: https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/). Public exploits for wp2shell were released in mid‑July, and active exploitation was observed shortly thereafter; we covered the exploit release and its mechanics in detail in Public Exploits Released for Critical wp2shell RCE Vulnerabilities in WordPress Core. The attacker used a custom wp2shell variant to breach at least 49 organizations in 29 countries, including a Western government organization. After gaining foothold, the threat actor performed extensive reconnaissance, checking Microsoft Defender, AMSI, listening ports, local accounts, and database configurations over a period of roughly 36 minutes. They attempted 17 scripts to bypass AMSI, escalated privileges via token impersonation or theft, created a local administrator account, and extracted registry data (Source: https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/).

Exploitation of ZyXEL GS1900 Switches

In addition to WordPress, the campaign exploited a high‑severity flaw in ZyXEL GS1900 Smart Managed Switches, tracked as CVE‑2026‑7273 (Source: https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/). This vulnerability allowed the attacker to compromise 996 devices across 48 countries, extracting device configurations, network information, and hashed root‑level credentials. The exploitation chain began on August 17, 2026, when the attacker started leveraging the ZyXEL flaw to gain initial access to network infrastructure, subsequently using the stolen credentials in a password‑spraying attack against an internal SQL server (Source: https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/). The severity of this exposure is reflected in the response: as we reported in ZyXEL Switch Flaw Moves Onto Federal Patch Priority List Amid Reported Data Theft, the flaw was pushed onto the federal patch‑priority list amid reports of stolen data.

Additional Exploited Vulnerabilities

The threat actor also chained multiple other vulnerabilities to broaden impact. These include:

Impact on Victims

The stolen data comprised accounts, plaintext passwords, and personally identifiable information tied to government and law‑enforcement agencies, exposing more than 18,500 records (Source: https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/). The breach also included device configurations and network topology details from compromised ZyXEL switches, which could aid future attacks. A notable “red‑on‑red” incident involved the compromise of a Russian state organization operating in occupied Ukraine, highlighting the geopolitical reach of the campaign (Source: https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/).

Campaign Timeline

GreyNoise first flagged anomalous traffic linked to the threat actor in early June 2026, noting scans and attacks originating from a consistent IP address (Source: https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/). The campaign intensified after public exploits for the wp2shell vulnerability (CVE‑2026‑63030 and CVE‑2026‑60137) were released in mid‑July, with active exploitation observed a few days later (Source: https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/). On August 17, 2026, the attacker began leveraging CVE‑2026‑7273 in ZyXEL GS1900 switches, compromising 996 devices across 48 countries and extracting configurations and hashed root credentials (Source: https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/). Subsequent chaining of additional vulnerabilities, including Ubiquiti UniFi OS flaws (CVE‑2026‑34908‑34910) and FlowiseAI (CVE‑2026‑56271), expanded the attack surface and allowed deeper network infiltration (Source: https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/).

Mitigation and Response

GreyNoise provided a set of indicators of compromise (IoCs), including hashes for custom backdoors and command‑and‑control infrastructure, to assist defenders (Source: https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/). CISA has flagged the ZyXEL GS1900 flaw and several Ubiquiti vulnerabilities as actively exploited, urging federal agencies to apply patches promptly (Source: https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/). Recommendations include:

  • Applying vendor patches for CVE‑2026‑7273 (ZyXEL) and CVE‑2026‑34908‑34910 (Ubiquiti) without delay.
  • Enforcing strict access controls on WordPress installations, disabling unnecessary plugins, and monitoring for wp2shell activity.
  • Implementing network segmentation to limit lateral movement after initial compromise.
  • Conducting regular credential audits and employing multi‑factor authentication to mitigate password‑spraying attacks.
  • Monitoring for anomalous traffic patterns and using threat intelligence feeds such as GreyNoise to detect early signs of exploitation (Source: https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/).

Future Outlook: A Supply Chain Compromise Template

Defenders should treat this campaign as a template for future multi‑vector attacks, especially those that combine web‑shell exploits with network‑device compromises. The pattern is familiar from recent supply chain compromise incidents: attackers poison or exploit trusted components — packages, plugins, and network appliances — and let victims' own trust do the rest. Recent cases such as the Red Hat npm Packages Compromised in Supply-Chain Attack Distributing Miasma Malware show the same logic of abusing software and infrastructure that organizations already rely on. Continuous monitoring of emerging exploits, rapid patch deployment, and robust network segmentation are essential to reduce the attack surface. Regular threat‑intel sharing with agencies such as CISA and GreyNoise will help maintain early detection and swift response.

introduction

More blogs