A suspected Chinese-speaking threat actor compromised a Philippine nuclear research agency and a naval-linked engineering firm by exploiting known vulnerabilities in ownCloud and WordPress software systems.
Key Points
- Researchers at Hunt.io discovered an exposed server in Amsterdam containing 1.17 GB of stolen data, logs, and offensive tools like Sliver and Metasploit.
- The nuclear research body was breached via CVE-2023-49105, an authentication-bypass flaw in ownCloud that allowed unauthorized file retrieval without credentials.
- The marine engineering company was compromised through CVE-2024-28000, a privilege-escalation vulnerability in the LiteSpeed Cache WordPress plugin.
- Stolen materials included nuclear reactor databases, radiation-safety documents, personnel records, and financial disclosures from Philippine officials.
- Attackers utilized custom Python scripts with random delays to exfiltrate data slowly, attempting to evade detection by security monitoring systems.