Chinese-Linked Group Exploits WordPress, Zyxel Flaws to Steal Government Data
A Chinese-speaking threat actor, potentially linked to the **Red Heron** group, has been actively exploiting critical vulnerabilities in **WordPress** and **Zyxel GS1900 Smart Managed Switches** to exfiltrate sensitive data from government organizations and other high-value targets across 29 countries. The campaign involves sophisticated reconnaissance and the theft of thousands of records, including plaintext passwords and PII.
A sophisticated Chinese-speaking threat actor has been observed leveraging a range of vulnerabilities, including critical flaws in **WordPress** and **Zyxel GS1900 Smart Managed Switches**, to conduct extensive data theft operations. The campaign, detected by threat intelligence firm **GreyNoise**, has compromised 996 devices and stolen over 18,500 records from backend databases, primarily targeting small businesses and government entities.
Attacks, originating from a consistent IP address, have been recorded since early June 2026 and are attributed to a threat actor associated with the **Red Heron** group. This group has previously been linked to exploiting a critical flaw in the **Gitea** self-hosted Git service.
## WordPress Exploitation Leads to Government Data Theft
The adversary exploited the **wp2shell** vulnerabilities (**CVE-2026-63030** and **CVE-2026-60137**) in **WordPress Core**, breaching at least 49 organizations across 29 countries. Public exploits for **wp2shell** became available in mid-July, with active exploitation observed shortly thereafter, coinciding with the start of **GreyNoise**'s observed campaign.
One notable intrusion involved an unnamed Western government organization. The attacker used a custom **wp2shell** exploit to perform extensive reconnaissance on Windows systems, checking for **Microsoft Defender**, **AMSI**, available services, listening ports, local accounts, application restrictions, and database configurations. Over 36 minutes, the threat actor deployed 17 scripts in an attempt to bypass **AMSI**, escalate privileges through token impersonation, create local administrators, and extract registry data.
After successfully locating credentials for a backend SQL database, the attackers initiated a password-spraying attack to gain access to an internal SQL server. From this server, they stole at least 18,566 records containing accounts, plaintext passwords, and personally identifiable information (PII) linked to government and law enforcement agencies.

In a separate incident described as a βred-on-redβ compromise, the same attacker also breached a Russian state organization located in occupied Ukraine.
## Exploiting a Multitude of Flaws
Beyond **WordPress**, the threat actor has actively exploited a high-severity flaw (**CVE-2026-7273**) in **Zyxel GS1900 Smart Managed Switches** since August 17, compromising 996 devices in 48 countries. This allowed them to extract device configurations, network information, and hashed root-level credentials.
.jpg)
The hackers also attempted to chain **Ubiquiti UniFi OS** vulnerabilities (**CVE-2026-34908**, **CVE-2026-34909**, and **CVE-2026-34910**) to achieve root-level remote code execution. **CISA** has flagged these three **Ubiquiti** flaws as actively exploited since late June 2026.
**GreyNoise** has further confirmed targeting of **PAN-OS GlobalProtect**, **FlowiseAI** (**CVE-2026-56271**), the **Linux kernel**'s **Dirty Pipe** flaw (**CVE-2022-0847**), **Gitea** (**CVE-2026-60004**), **Nuclio** (**CVE-2026-79756**), **SENAITE LIMS** (**CVE-2026-54569**), and **Proxmox VE** (**CVE-2023-54391**).
It's important to note that not all security issues leveraged in attacks by this threat cluster have yet been added to **CISA**'s catalog of Known Exploited Vulnerabilities (KEV).
**GreyNoise** has provided a set of Indicators of Compromise (IoCs) related to the observed activity, including hashes for backdoors and command-and-control (C2) infrastructure, to aid defenders in detection and mitigation.