Threat reportVulnerabilityTL-2026-2172
Suspected Chinese-Speaking Threat Actor Exploits ownCloud and WordPress Flaws to Steal Philippine Nuclear and Naval Data
Suspected Chinese-Speaking Threat Actor Exploits ownCloud (TL-2026-2172) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-08-27 and last reviewed 2026-09-02. It is linked to a China-nexus actor with low confidence, affects ownCloud ownCloud Server, references 2 CVEs (CVE-2023-49105, CVE-2024-28000), maps to 21 MITRE ATT&CK techniques (T1020, T1059.006, T1068), and is covered by 9 detection rules and 40 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 21MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 40Indicators of compromise
Key facts for TL-2026-2172
- Threat ID
- TL-2026-2172
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- government administration, nuclear, defense, maritime, research
- Target regions
- Southeast Asia, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 40
- Updates
- 2026-09-02 · 3 updates · revalidated 3× · latest source
Malware and tooling in Suspected Chinese-Speaking Threat Actor Exploits ownCloud
Malware and tooling: Meterpreter (Android), Mettle, Mettle, Sliver - S0633, rockyou.txt
How Suspected Chinese-Speaking Threat Actor Exploits ownCloud works
A suspected Chinese-speaking operator chained CVE-2023-49105 (ownCloud pre-signed URL authentication bypass) and CVE-2024-28000 (LiteSpeed Cache WordPress privilege escalation) to breach a Philippine nuclear research body and a naval marine-engineering contractor, stealing roughly 9 GB of reactor, personnel, and encrypted-credential data plus 195 MB from the contractor's WordPress site. Hunt.io discovered the campaign after finding an openly accessible attacker-controlled server staging Python exploit scripts, an ELF loader, and a Mettle payload alongside the stolen files.
Hunt.io identified an open directory on 31.58.209[.]241:8000 on 2026-08-13 that exposed the tooling and take of an intrusion set targeting Philippine government-linked organizations. The initial foothold against the nuclear research body's ownCloud deployment exploited CVE-2023-49105, a critical authentication bypass (CVSS 9.8) in the pre-signed URL/WebDAV signing mechanism: when an ownCloud instance has no signing key configured, the server's signing routine silently falls back to an empty secret, letting anyone who knows a valid username forge a PBKDF2-HMAC-SHA512-signed WebDAV request (10,000 iterations, empty b"" key) and retrieve or manipulate that user's files without ever supplying credentials.
Five near-identical Python scripts recovered from the staging server implement this technique. Four target a single ownCloud account each, issuing GET requests against /remote.php/dav/files/<account>/<path> with a forged OC-Signature and randomized 3-6 second delays between requests to evade rate-limiting. The fifth, oc_vps_download.py, is a more advanced enumerator that issues WebDAV PROPFIND requests with Depth: 1 to recursively map account file trees, tightens its delay to 1.5-3.5 seconds, and logs every retrieval to /root/oc_download.log. Using this access the operator staged roughly 9 GB of data referenced in a CSV manifest named after the victim's parent ministry; Hunt.io itself recovered 176 files (~372 MB) across five categories spanning reactor-operations records, radiation-safety documentation, strategic/IT planning material, and 130 MB of personnel/PII, plus a KEYS subfolder containing KeePass databases, AxCrypt-encrypted files, and BitLocker recovery keys. A separate 192 MB SQL dump of a ZKTeco BioTime attendance/personnel database, also recovered from the top-level of the same open directory, referenced additional Philippine government science and research organizations.
Against the naval marine-engineering and shipbuilding contractor's WordPress site, the operator exploited CVE-2024-28000, an unauthenticated privilege-escalation flaw (CVSS 9.8) in the LiteSpeed Cache plugin. The flaw lets an attacker who obtains or brute-forces a debug-log hash spoof the plugin's role-simulation feature to impersonate an administrator, then create a new administrator account via the /wp-json/wp/v2/users REST API endpoint. Compiled Go exploit binaries (wp28000, wp28000_cp) and their source (main.go) were found alongside brute_xmlrpc.py, which brute-forced WordPress credentials via XML-RPC wp.getUsersBlogs calls using the rockyou.txt wordlist, and brute_result.txt logging successful hits. Three archives totaling 195 MB -- the full site tree, a database dump, and the media library -- were staged from this intrusion.
The same 31.58.209[.]241 host also served a stage-1 ELF loader (multi_backupd, SHA-256 7447d0d0c34779d4c519823b39bf6ddc16d2b34a226b82ee69da6f5b4a77ad82) and, from port 8090, a Mettle (portable Meterpreter) stage-two payload (stage2_payload.bin, SHA-256 10df3451915ea35bcb17efe121415f24182680e2d07fc09df07ee695072104c1). A Sliver C2 framework installation was also present on the server, though Hunt.io did not directly attribute its use to a specific intrusion step. Additional service fingerprints on the host included a cloned ownCloud login page on port 80, OpenSSH 9.6p1 Ubuntu on port 22, a Python 3.12.3 BaseHTTP responder on port 8080, and a raw TCP listener on port 54329.
Attribution rests on circumstantial but consistent evidence: stolen files were sorted into folders labelled in simplified Chinese (财务/Finance, 辐射安全/Radiation Safety, 核材料账目/Nuclear Material Accounts, IT规划/IT Planning, 系统文档/System Documentation), and script docstrings describe "low-speed download" operations against nuclear-material and radiation-safety documents in Chinese. No named group was attributed. Hunt.io disclosed its findings to CERT-PH under TLP:AMBER, which notified the affected organizations before the embargo lifted on 2026-08-25; Hunt.io published its report on 2026-08-26, assessing with medium confidence that the activity reflects targeted rather than opportunistic collection, given the reactor/naval-specific targeting despite the underlying vulnerabilities being broadly exploitable.
MITRE ATT&CK techniques used in TL-2026-2172
Exfiltration
Execution
T1059.006 Command and Scripting Interpreter: Python; T1204 User Execution: Malicious File
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Command and Control
T1071 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer
Collection
T1074.001 Data Staged: Local Data Staging; T1074.002 Data Staged: Remote Data Staging; T1213 Data from Information Repositories; T1560 Archive Collected Data
Discovery
T1083 File and Directory Discovery
Credential Access
T1110.001 Brute Force: Password Guessing; T1552.001 Unsecured Credentials: Credentials In Files
Persistence
T1136.001 Create Account: Local Account
Initial Access
T1190 Exploit Public-Facing Application
Defense Evasion
T1218 System Binary Proxy Execution: Mshta
Resource Development
T1583.003 Acquire Infrastructure: Virtual Private Server; T1587.001 Develop Capabilities: Malware; T1587.004 Develop Capabilities: Exploits; T1588.002 Obtain Capabilities: Tool; T1608.002 Stage Capabilities: Upload Tool
Affected products and versions in Suspected Chinese-Speaking Threat Actor Exploits ownCloud
- ownCloud — ownCloud Server
Vulnerable versions: 10.6.0-10.13.0
Fixed in: 10.13.1 (CVE-2023-49105 fix); 10.13.3 (vendor-recommended, also fixes CVE-2023-49103/CVE-2023-49104) - LiteSpeed Technologies — LiteSpeed Cache (WordPress plugin)
Vulnerable versions: 1.9-6.3.0.1
Fixed in: 6.4
Remediation for Suspected Chinese-Speaking Threat Actor Exploits ownCloud
Patches
- ownCloud Server 10.13.1 (CVE-2023-49105) / 10.13.3 vendor-recommended bundle
- LiteSpeed Cache plugin 6.4
Immediate actions
- Patch ownCloud Server to 10.13.1 (fixes CVE-2023-49105) or the vendor-recommended 10.13.3 (also fixes CVE-2023-49103/CVE-2023-49104)
- Update the LiteSpeed Cache WordPress plugin to version 6.4 or later
- Rotate all credentials, signing keys, and secrets stored in or accessible via unpatched ownCloud or WordPress instances
- Audit WordPress administrator accounts for entries created without a known owner via the REST API
- Block and hunt for connections to/from 31.58.209.241
Workarounds
- Explicitly configure an ownCloud signing key on every instance so pre-signed URL validation cannot fall back to an empty secret
- Disable or restrict the LiteSpeed Cache role-simulation/debug-log feature until the plugin is patched
Longer-term hardening
- Deploy WebDAV/REST API anomaly detection for PROPFIND enumeration bursts and mismatched OC-Signature/OC-Credential headers
- Disable XML-RPC on WordPress installations that do not require it, or restrict access to trusted IPs
- Enforce MFA and request rate-limiting on all internet-facing ownCloud and WordPress logins
- Isolate nuclear/critical-infrastructure research data behind access controls independent of the file-sharing platform's own authentication
CVEs associated with Suspected Chinese-Speaking Threat Actor Exploits ownCloud
Weaknesses (CWE) in Suspected Chinese-Speaking Threat Actor Exploits ownCloud
Timeline of Suspected Chinese-Speaking Threat Actor Exploits ownCloud
- ownCloud discloses CVE-2023-49105, a critical pre-signed URL authentication bypass in ownCloud Server versions before 10.13.1, alongside CVE-2023-49103 and CVE-2023-49104.
- LiteSpeed Cache plugin version 6.4 is released, patching the unauthenticated privilege-escalation flaw later assigned CVE-2024-28000.
- Patchstack and LiteSpeed disclose CVE-2024-28000, an unauthenticated privilege-escalation flaw in the LiteSpeed Cache WordPress plugin (versions 1.9-6.3.0.1), patched in version 6.4.
- Latest records recovered from the ZKTeco BioTime attendance-system SQL dump on the actor's staging server are dated December 2024, indicating the actor's data holdings were current through at least that period.
- A Japanese-language security blog flags a NoChain malware service-worker script later found co-located on the same staging infrastructure, though not confidently linked to the nuclear/naval intrusion operator.
- Hunt.io identifies an open directory on 31.58.209[.]241:8000 hosting five custom Python exploit scripts, the multi_backupd ELF loader, a Mettle stage-two payload, and staged data stolen from a Philippine nuclear research body and a naval marine-engineering contractor.
- Hunt.io verifies active EtherHiding-style compromise via analysis of the Ethereum smart contract (0x58460d0b3d4d6b03761c89120393c0c676676496) used to deliver ClickFix loader content.
- Hunt.io's coordinated disclosure to CERT-PH under TLP:AMBER concludes; CERT-PH had notified the affected Philippine organizations ahead of public release.
- Hunt.io publishes its full technical report on the campaign at 16:55 UTC.
- CISA adds CVE-2023-49105 (ownCloud) to its Known Exploited Vulnerabilities catalog, citing confirmed active exploitation tied to this campaign against the Philippine nuclear research agency.
- Cyber Security News republishes and summarizes the Hunt.io findings, bringing the campaign to broader public attention.
- Security Affairs and other outlets publish summary coverage of the Hunt.io report, drawing renewed attention to the campaign.
- CISA BOD 26-04 remediation deadline for U.S. federal agencies to patch CVE-2023-49105.
Update history for TL-2026-2172
- 2026-09-02 — Suspected Chinese-Speaking Operator Exploits Old ownCloud and WordPress Flaws to Steal Philippine Nuclear Agency and Naval Contractor Data (CVE-2023-49105, CVE-2024-28000): What changed No field-level escalations are supported by this report; severity, exploitability, CVSS, status, and attribution_confidence are unchanged. The newer report supplies additional detail on a co-located EtherHiding/NoChain/ClickFix
- 2026-08-30 — CISA Adds ownCloud (CVE-2023-49105), Linux Kernel (CVE-2026-53362), and JFrog Artifactory (CVE-2026-66384) Flaws to KEV Catalog: What changed No severity/exploitability/status change (still CRITICAL/ACTIVE/ACTIVE). CVE-2023-49105 was added to CISA's Known Exploited Vulnerabilities catalog on 2026-08-27 with a federal BOD 26-04 remediation deadline of 2026-08-30, form
- 2026-08-29 — Suspected Chinese-Speaking Operator Breaches Philippine Nuclear Research Body and Naval Shipbuilding Supplier via ownCloud (CVE-2023-49105) and WordPress LiteSpeed Cache (CVE-2024-28000): What changed Severity HIGH - CRITICAL, reflecting a broader confirmed impact: a possible unconfirmed third victim (via the ZKTeco BioTime dump referencing other Philippine government science/research bodies) and more sensitive PII categorie
Sources cited for Suspected Chinese-Speaking Threat Actor Exploits ownCloud
- Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities
- Hackers Exploit ownCloud and WordPress Flaws to Steal Philippine Nuclear and Naval Data
- CVE-2023-49105 Detail - NVD
- CVE-2024-28000 Detail - NVD
- Immediate Action Required: Critical Security Updates for ownCloud
- Critical Privilege Escalation in LiteSpeed Cache Plugin
- Over 5,000,000 Site Owners Affected by Critical Privilege Escalation Vulnerability Patched in LiteSpeed Cache Plugin
- ownCloud exploits for CVE-2023-49105 (ambionics)
Detection coverage for TL-2026-2172
As of 2026-09-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2172 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.