Threat reportVulnerabilityTL-2026-2172

Suspected Chinese-Speaking Threat Actor Exploits ownCloud and WordPress Flaws to Steal Philippine Nuclear and Naval Data

criticalACTIVE

Suspected Chinese-Speaking Threat Actor Exploits ownCloud (TL-2026-2172) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-08-27 and last reviewed 2026-09-02. It is linked to a China-nexus actor with low confidence, affects ownCloud ownCloud Server, references 2 CVEs (CVE-2023-49105, CVE-2024-28000), maps to 21 MITRE ATT&CK techniques (T1020, T1059.006, T1068), and is covered by 9 detection rules and 40 indicators of compromise.

CVSS
9.8/10Critical
CVEs
2Referenced vulnerabilities
Techniques
21MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
40Indicators of compromise

Key facts for TL-2026-2172

Threat ID
TL-2026-2172
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
government administration, nuclear, defense, maritime, research
Target regions
Southeast Asia, Asia-Pacific
Detection rules
9
Indicators of compromise
40
Updates
2026-09-02 · 3 updates · revalidated 3× · latest source

Malware and tooling in Suspected Chinese-Speaking Threat Actor Exploits ownCloud

Malware and tooling: Meterpreter (Android), Mettle, Mettle, Sliver - S0633, rockyou.txt

How Suspected Chinese-Speaking Threat Actor Exploits ownCloud works

A suspected Chinese-speaking operator chained CVE-2023-49105 (ownCloud pre-signed URL authentication bypass) and CVE-2024-28000 (LiteSpeed Cache WordPress privilege escalation) to breach a Philippine nuclear research body and a naval marine-engineering contractor, stealing roughly 9 GB of reactor, personnel, and encrypted-credential data plus 195 MB from the contractor's WordPress site. Hunt.io discovered the campaign after finding an openly accessible attacker-controlled server staging Python exploit scripts, an ELF loader, and a Mettle payload alongside the stolen files.

Hunt.io identified an open directory on 31.58.209[.]241:8000 on 2026-08-13 that exposed the tooling and take of an intrusion set targeting Philippine government-linked organizations. The initial foothold against the nuclear research body's ownCloud deployment exploited CVE-2023-49105, a critical authentication bypass (CVSS 9.8) in the pre-signed URL/WebDAV signing mechanism: when an ownCloud instance has no signing key configured, the server's signing routine silently falls back to an empty secret, letting anyone who knows a valid username forge a PBKDF2-HMAC-SHA512-signed WebDAV request (10,000 iterations, empty b"" key) and retrieve or manipulate that user's files without ever supplying credentials.

Five near-identical Python scripts recovered from the staging server implement this technique. Four target a single ownCloud account each, issuing GET requests against /remote.php/dav/files/<account>/<path> with a forged OC-Signature and randomized 3-6 second delays between requests to evade rate-limiting. The fifth, oc_vps_download.py, is a more advanced enumerator that issues WebDAV PROPFIND requests with Depth: 1 to recursively map account file trees, tightens its delay to 1.5-3.5 seconds, and logs every retrieval to /root/oc_download.log. Using this access the operator staged roughly 9 GB of data referenced in a CSV manifest named after the victim's parent ministry; Hunt.io itself recovered 176 files (~372 MB) across five categories spanning reactor-operations records, radiation-safety documentation, strategic/IT planning material, and 130 MB of personnel/PII, plus a KEYS subfolder containing KeePass databases, AxCrypt-encrypted files, and BitLocker recovery keys. A separate 192 MB SQL dump of a ZKTeco BioTime attendance/personnel database, also recovered from the top-level of the same open directory, referenced additional Philippine government science and research organizations.

Against the naval marine-engineering and shipbuilding contractor's WordPress site, the operator exploited CVE-2024-28000, an unauthenticated privilege-escalation flaw (CVSS 9.8) in the LiteSpeed Cache plugin. The flaw lets an attacker who obtains or brute-forces a debug-log hash spoof the plugin's role-simulation feature to impersonate an administrator, then create a new administrator account via the /wp-json/wp/v2/users REST API endpoint. Compiled Go exploit binaries (wp28000, wp28000_cp) and their source (main.go) were found alongside brute_xmlrpc.py, which brute-forced WordPress credentials via XML-RPC wp.getUsersBlogs calls using the rockyou.txt wordlist, and brute_result.txt logging successful hits. Three archives totaling 195 MB -- the full site tree, a database dump, and the media library -- were staged from this intrusion.

The same 31.58.209[.]241 host also served a stage-1 ELF loader (multi_backupd, SHA-256 7447d0d0c34779d4c519823b39bf6ddc16d2b34a226b82ee69da6f5b4a77ad82) and, from port 8090, a Mettle (portable Meterpreter) stage-two payload (stage2_payload.bin, SHA-256 10df3451915ea35bcb17efe121415f24182680e2d07fc09df07ee695072104c1). A Sliver C2 framework installation was also present on the server, though Hunt.io did not directly attribute its use to a specific intrusion step. Additional service fingerprints on the host included a cloned ownCloud login page on port 80, OpenSSH 9.6p1 Ubuntu on port 22, a Python 3.12.3 BaseHTTP responder on port 8080, and a raw TCP listener on port 54329.

Attribution rests on circumstantial but consistent evidence: stolen files were sorted into folders labelled in simplified Chinese (财务/Finance, 辐射安全/Radiation Safety, 核材料账目/Nuclear Material Accounts, IT规划/IT Planning, 系统文档/System Documentation), and script docstrings describe "low-speed download" operations against nuclear-material and radiation-safety documents in Chinese. No named group was attributed. Hunt.io disclosed its findings to CERT-PH under TLP:AMBER, which notified the affected organizations before the embargo lifted on 2026-08-25; Hunt.io published its report on 2026-08-26, assessing with medium confidence that the activity reflects targeted rather than opportunistic collection, given the reactor/naval-specific targeting despite the underlying vulnerabilities being broadly exploitable.

MITRE ATT&CK techniques used in TL-2026-2172

Exfiltration

T1020 Automated Exfiltration

Execution

T1059.006 Command and Scripting Interpreter: Python; T1204 User Execution: Malicious File

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer

Collection

T1074.001 Data Staged: Local Data Staging; T1074.002 Data Staged: Remote Data Staging; T1213 Data from Information Repositories; T1560 Archive Collected Data

Discovery

T1083 File and Directory Discovery

Credential Access

T1110.001 Brute Force: Password Guessing; T1552.001 Unsecured Credentials: Credentials In Files

Persistence

T1136.001 Create Account: Local Account

Initial Access

T1190 Exploit Public-Facing Application

Defense Evasion

T1218 System Binary Proxy Execution: Mshta

Resource Development

T1583.003 Acquire Infrastructure: Virtual Private Server; T1587.001 Develop Capabilities: Malware; T1587.004 Develop Capabilities: Exploits; T1588.002 Obtain Capabilities: Tool; T1608.002 Stage Capabilities: Upload Tool

Affected products and versions in Suspected Chinese-Speaking Threat Actor Exploits ownCloud

  • ownCloud — ownCloud Server
    Vulnerable versions: 10.6.0-10.13.0
    Fixed in: 10.13.1 (CVE-2023-49105 fix); 10.13.3 (vendor-recommended, also fixes CVE-2023-49103/CVE-2023-49104)
  • LiteSpeed Technologies — LiteSpeed Cache (WordPress plugin)
    Vulnerable versions: 1.9-6.3.0.1
    Fixed in: 6.4

Remediation for Suspected Chinese-Speaking Threat Actor Exploits ownCloud

Patches

  • ownCloud Server 10.13.1 (CVE-2023-49105) / 10.13.3 vendor-recommended bundle
  • LiteSpeed Cache plugin 6.4

Immediate actions

  • Patch ownCloud Server to 10.13.1 (fixes CVE-2023-49105) or the vendor-recommended 10.13.3 (also fixes CVE-2023-49103/CVE-2023-49104)
  • Update the LiteSpeed Cache WordPress plugin to version 6.4 or later
  • Rotate all credentials, signing keys, and secrets stored in or accessible via unpatched ownCloud or WordPress instances
  • Audit WordPress administrator accounts for entries created without a known owner via the REST API
  • Block and hunt for connections to/from 31.58.209.241

Workarounds

  • Explicitly configure an ownCloud signing key on every instance so pre-signed URL validation cannot fall back to an empty secret
  • Disable or restrict the LiteSpeed Cache role-simulation/debug-log feature until the plugin is patched

Longer-term hardening

  • Deploy WebDAV/REST API anomaly detection for PROPFIND enumeration bursts and mismatched OC-Signature/OC-Credential headers
  • Disable XML-RPC on WordPress installations that do not require it, or restrict access to trusted IPs
  • Enforce MFA and request rate-limiting on all internet-facing ownCloud and WordPress logins
  • Isolate nuclear/critical-infrastructure research data behind access controls independent of the file-sharing platform's own authentication

CVEs associated with Suspected Chinese-Speaking Threat Actor Exploits ownCloud

CVE-2023-49105, CVE-2024-28000

Weaknesses (CWE) in Suspected Chinese-Speaking Threat Actor Exploits ownCloud

CWE-287, CWE-266, CWE-665

Timeline of Suspected Chinese-Speaking Threat Actor Exploits ownCloud

  • ownCloud discloses CVE-2023-49105, a critical pre-signed URL authentication bypass in ownCloud Server versions before 10.13.1, alongside CVE-2023-49103 and CVE-2023-49104.
  • LiteSpeed Cache plugin version 6.4 is released, patching the unauthenticated privilege-escalation flaw later assigned CVE-2024-28000.
  • Patchstack and LiteSpeed disclose CVE-2024-28000, an unauthenticated privilege-escalation flaw in the LiteSpeed Cache WordPress plugin (versions 1.9-6.3.0.1), patched in version 6.4.
  • Latest records recovered from the ZKTeco BioTime attendance-system SQL dump on the actor's staging server are dated December 2024, indicating the actor's data holdings were current through at least that period.
  • A Japanese-language security blog flags a NoChain malware service-worker script later found co-located on the same staging infrastructure, though not confidently linked to the nuclear/naval intrusion operator.
  • Hunt.io identifies an open directory on 31.58.209[.]241:8000 hosting five custom Python exploit scripts, the multi_backupd ELF loader, a Mettle stage-two payload, and staged data stolen from a Philippine nuclear research body and a naval marine-engineering contractor.
  • Hunt.io verifies active EtherHiding-style compromise via analysis of the Ethereum smart contract (0x58460d0b3d4d6b03761c89120393c0c676676496) used to deliver ClickFix loader content.
  • Hunt.io's coordinated disclosure to CERT-PH under TLP:AMBER concludes; CERT-PH had notified the affected Philippine organizations ahead of public release.
  • Hunt.io publishes its full technical report on the campaign at 16:55 UTC.
  • CISA adds CVE-2023-49105 (ownCloud) to its Known Exploited Vulnerabilities catalog, citing confirmed active exploitation tied to this campaign against the Philippine nuclear research agency.
  • Cyber Security News republishes and summarizes the Hunt.io findings, bringing the campaign to broader public attention.
  • Security Affairs and other outlets publish summary coverage of the Hunt.io report, drawing renewed attention to the campaign.
  • CISA BOD 26-04 remediation deadline for U.S. federal agencies to patch CVE-2023-49105.

Update history for TL-2026-2172

Sources cited for Suspected Chinese-Speaking Threat Actor Exploits ownCloud

Detection coverage for TL-2026-2172

As of 2026-09-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2172 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
40 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats