Hacker cinesi violano 996 dispositivi WordPress e ZyXEL, rubati 18.500 record

Dati personali e credenziali di agenti di polizia e funzionari governativi sono stati rubati, compromettendo la sicurezza e la privacy di migliaia di individui legati ad agenzie pubbliche.
In 36 minuti hanno testato 17 script diversi per aggirare le difese
La velocità e la precisione dell'attacco a un'agenzia governativa occidentale rivela una preparazione meticolosa.
Mark

Chi è il gruppo Red Heron e come lo hanno identificato?

Mimi

GreyNoise ha collegato l'attività a Red Heron attraverso l'indirizzo IP utilizzato in modo sistematico durante tutta la campagna. Red Heron è già noto per aver sfruttato vulnerabilità critiche in Gitea. Quello che rende questa campagna diversa è la scala e la coordinazione.

Luke

Ma è importante notare che il collegamento a Red Heron è un'attribuzione basata su pattern tecnici, non su una confessione o su intelligence governativa. GreyNoise ha visibilità sulla rete, ma attribuire un attacco a un gruppo specifico rimane sempre una conclusione, non una certezza assoluta.

Mark

Perché hanno rubato 18.500 record da un'agenzia governativa occidentale? Cosa ci fanno con quei dati?

Mimi

I record contenevano account, password in chiaro e informazioni personali di agenti di polizia e funzionari governativi. Questi dati hanno valore sia per il ricatto che per l'accesso continuato alle infrastrutture. Le credenziali possono essere riutilizzate in altri attacchi.

Luke

Vero, ma il rapporto di GreyNoise non specifica se i dati siano stati venduti, utilizzati per accessi successivi, o semplicemente estratti come prova di compromissione. Sappiamo cosa è stato rubato, ma non ancora come viene utilizzato.

Mark

Cosa significa che non tutte le vulnerabilità sono nel catalogo CISA KEV?

Mimi

Significa che alcuni dei buchi di sicurezza sfruttati in questa campagna non sono ancora nella lista ufficiale delle vulnerabilità attivamente sfruttate. Gli attaccanti mantengono un vantaggio: i difensori potrebbero non sapere che queste falle sono già sotto attacco.

Luke

Esatto. È un divario informativo pericoloso. Se una vulnerabilità non è nel KEV, i team di sicurezza potrebbero non darle priorità nel patching. Gli attaccanti lo sanno e ne approfittano.

Mark

Hanno attaccato anche la Russia?

Mimi

Sì, hanno compromesso un'organizzazione statale russa in territorio ucraino occupato. I ricercatori lo hanno definito un compromesso "red on red", il che suggerisce una dinamica geopolitica complessa.

Luke

È un dettaglio interessante ma poco approfondito nel rapporto. Non sappiamo se fosse un bersaglio secondario, se l'attacco sia stato coordinato con altri attori, o se sia semplicemente una conseguenza della loro ampia ricerca di bersagli vulnerabili.

  • 996 dispositivi compromessi in 48 paesi
  • 18.566 record rubati da un'agenzia governativa occidentale
  • Vulnerabilità wp2shell (CVE-2026-63030 e CVE-2026-60137) hanno colpito almeno 49 organizzazioni in 29 paesi
  • Campagna sistematica tracciata da un singolo indirizzo IP dal giugno 2026
  • Attacchi a ZyXEL GS1900, Ubiquiti UniFi OS, PAN-OS GlobalProtect e altre tecnologie

Gli attaccanti hanno usato vulnerabilità wp2shell per violare almeno 49 organizzazioni in 29 paesi, colpendo in particolare un ente governativo occidentale da cui hanno estratto dati sensibili di agenzie di polizia. Una campagna coordinata ha sfruttato falle in ZyXEL GS1900, Ubiquiti UniFi OS, PAN-OS GlobalProtect e altre tecnologie, con attività sistematica tracciata da un singolo indirizzo IP collegato al gruppo Red Heron.

Un gruppo di hacker cinesi ha sfruttato vulnerabilità in WordPress e switch ZyXEL per compromettere 996 dispositivi e rubare oltre 18.500 record da enti pubblici e forze dell'ordine in una campagna sistematica dal giugno 2026.

A Chinese hacking group has spent months methodically breaking into government agencies and police forces across the Western world, exploiting known security gaps in WordPress installations and network switches to steal tens of thousands of sensitive records. The campaign, tracked by threat intelligence firm GreyNoise, began in June 2026 and has compromised 996 devices across 48 countries, extracting more than 18,500 database records containing account credentials, plaintext passwords, and personal information tied to law enforcement and government officials.

The attackers operated with clear purpose and patience. They used two WordPress vulnerabilities, catalogued as CVE-2026-63030 and CVE-2026-60137 and collectively known as wp2shell, to breach at least 49 organizations spread across 29 countries. Public exploits for these flaws appeared in mid-July; within days, the same group was already using them in active attacks. The targeting was precise. While many victims were small businesses and public administration offices, one intrusion stood out: a Western government agency whose name has not been disclosed. There, the attackers deployed a customized version of the wp2shell exploit and then conducted an exhaustive reconnaissance of the Windows environment, probing Microsoft Defender settings, AMSI protections, running services, open ports, local accounts, application restrictions, and database configurations. In 36 minutes, they tested 17 different scripts designed to bypass AMSI defenses, escalate privileges through token theft and impersonation, create new administrator accounts, and extract data from the system registry. Once they identified credentials for a backend SQL database, they used password spraying to gain access to an internal SQL server. From that server, they stole at least 18,566 records—account information, passwords stored in plaintext, and personal details belonging to government and police agencies. The same actor also breached a Russian state organization operating in occupied Ukrainian territory, an incident researchers described as a red-on-red compromise.

The campaign expanded in scope on August 17, when the group shifted focus to network infrastructure. They exploited a high-severity vulnerability in ZyXEL GS1900 Smart Managed switches, tracked as CVE-2026-7273, targeting 996 devices in 48 countries. From these switches, they extracted network configurations, infrastructure details, and root credentials in hash format—valuable intelligence for moving deeper into target networks without detection. Simultaneously, they attempted to chain together three vulnerabilities in Ubiquiti UniFi OS, designated CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, to achieve remote code execution with root privileges. The U.S. Cybersecurity and Infrastructure Security Agency had already flagged these three flaws as actively exploited since late June 2026.

The breadth of the group's toolkit is striking. Beyond WordPress and ZyXEL, researchers confirmed attack attempts against Palo Alto Networks PAN-OS GlobalProtect, FlowiseAI, the Linux kernel vulnerability Dirty Pipe, Gitea, Nuclio, SENAITE LIMS, and Proxmox VE. Each target represented a documented security flaw with a known patch. Yet a troubling detail emerged: not all the vulnerabilities used in this cluster of attacks have been added to the CISA Known Exploited Vulnerabilities catalog, the authoritative list of flaws known to be actively exploited in the wild. That gap suggests the attackers maintain a tactical advantage and may continue striking unpatched infrastructure before defenders can fully respond. GreyNoise has released indicators of compromise tied to the observed activity, including backdoor hashes and references to command-and-control infrastructure, but the group's next moves remain unknown.

Una campagna lunga, ordinata, condotta sempre dallo stesso indirizzo IP
— GreyNoise, società di threat intelligence
Non tutte le vulnerabilità usate in questo cluster di attacchi sono state inserite nel catalogo CISA KEV
— Ricercatori GreyNoise
Contattaci Domande frequenti