Activity timeline
Kapibala appears in 2 tracked threats between and .
ATT&CK techniques observed
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 2 of 2 tracked threats
- T1552.001 Unsecured Credentials — Credential Accessobserved in 2 of 2 tracked threats
- T1005 Data from Local System — Collectionobserved in 1 of 2 tracked threats
- T1014 Rootkit — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
- T1021.004 SSH — Lateral Movementobserved in 1 of 2 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
- T1027.002 Software Packing — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
- T1059.004 Unix Shell — Executionobserved in 1 of 2 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 1 of 2 tracked threats
- T1071.002 File Transfer Protocols — Command and Controlobserved in 1 of 2 tracked threats
- T1078.001 Default Accounts — Initial Accessobserved in 1 of 2 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 1 of 2 tracked threats
- T1110.003 Password Spraying — Credential Accessobserved in 1 of 2 tracked threats
- T1134.001 Token Impersonation/Theft — Privilege Escalationobserved in 1 of 2 tracked threats
- T1136.001 Local Account — Persistenceobserved in 1 of 2 tracked threats
Tracked threats
- Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti UniFi OS Flaws to Steal Government DataCRITICAL
- Zyxel GS1900 Series Switches Stack-Based Buffer Overflow (CVE-2026-7273) Actively Exploited by Kapibala/Red Heron in Global 996-Device Campaign — Added to CISA KEVCRITICAL