
A suspected Chinese-speaking threat actor exploited WordPress vulnerabilities to breach dozens of organizations worldwide, stealing more than 18,000 sensitive records from one Western government agency.
GreyNoise researchers tracked the attacker through the company’s Global Observation Grid (GOG), a network of internet-facing sensors designed to attract scanning and exploitation attempts. GreyNoise says it has monitored malicious activity tied to the same infrastructure since early June 2026, while activity observed from May 7 onward appears to belong to a single actor.
GreyNoise assesses that the attacker may be a Chinese speaker operating around the UTC+8 time zone, based partly on working hours and extensive Chinese-language comments inside custom scripts. The researchers also found links to the “Red Heron” activity previously documented by Acronis, including shared command-and-control infrastructure, malware, and targeting patterns.
WordPress is the world’s most widely used content management system and powers websites ranging from small businesses to major organizations and government agencies. Its popularity also makes vulnerable or outdated installations attractive targets for attackers looking to compromise large numbers of sites.
Around July 20, the attacker began exploiting a WordPress attack chain known as “wp2shell,” which uses CVE-2026-63030 and CVE-2026-60137. GreyNoise identified at least 49 compromised organizations across 29 countries, primarily small businesses and government bodies.
The most serious breach involved an unnamed Western government organization. According to a timeline reconstructed from file timestamps, the attacker compromised the WordPress site on July 22, installed a webshell, dumped administrator accounts, created a disguised WordPress user, and uploaded tools for gathering information about the underlying server.
The attacker then searched accessible files for stored credentials and found working login details for a backend SQL database. Those credentials were subsequently used to access the database and extract at least 18,566 records containing account information, plaintext passwords, and personally identifiable information associated with government and law-enforcement organizations.
GreyNoise also observed the attacker attempting privilege escalation, internal password spraying, and security-control bypasses. Researchers noted that the rapid development of multiple custom scripts, along with superficial changes between versions and verbose Chinese comments, suggests some of the tooling may have been produced with the help of a large language model.
The same actor later targeted ZyXEL GS1900 Smart Managed Switches using CVE-2026-7273. GreyNoise says the attacker compromised 996 switches across 48 countries and collected configuration files, network information, and hashed root credentials. Of those systems, 564 were still using factory-default credentials.

Organizations running affected WordPress installations should apply available security updates immediately, review administrator accounts and recently added plugins, and inspect servers for unexpected webshells or credential-access activity. Network administrators using ZyXEL GS1900 switches should also update vulnerable firmware, replace default credentials, and review devices for unauthorized configuration changes or outbound connections.







Leave a Reply