# Suspected Chinese-Speaking Threat Actor Exploits ownCloud and WordPress Flaws to Steal Philippine Nuclear and Naval Data

> A suspected Chinese-speaking operator chained CVE-2023-49105 (ownCloud pre-signed URL authentication bypass) and CVE-2024-28000 (LiteSpeed Cache WordPress privilege escalation) to breach a Philippine nuclear research body and a naval marine-engineering contractor, stealing roughly 9 GB of reactor, personnel, and encrypted-credential data plus 195 MB from the contractor's WordPress site. Hunt.io discovered the campaign after finding an openly accessible attacker-controlled server staging Python exploit scripts, an ELF loader, and a Mettle payload alongside the stolen files.

- **Published:** 2026-08-27T00:00:00Z
- **Last reviewed:** 2026-09-02T01:29:00.667Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2172
- **ID:** TL-2026-2172
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 40 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2023-49105, CVE-2024-28000

## Description

Hunt.io identified an open directory on 31.58.209[.]241:8000 on 2026-08-13 that exposed the tooling and take of an intrusion set targeting Philippine government-linked organizations. The initial foothold against the nuclear research body's ownCloud deployment exploited CVE-2023-49105, a critical authentication bypass (CVSS 9.8) in the pre-signed URL/WebDAV signing mechanism: when an ownCloud instance has no signing key configured, the server's signing routine silently falls back to an empty secret, letting anyone who knows a valid username forge a PBKDF2-HMAC-SHA512-signed WebDAV request (10,000 iterations, empty b"" key) and retrieve or manipulate that user's files without ever supplying credentials.

Five near-identical Python scripts recovered from the staging server implement this technique. Four target a single ownCloud account each, issuing GET requests against /remote.php/dav/files/<account>/<path> with a forged OC-Signature and randomized 3-6 second delays between requests to evade rate-limiting. The fifth, oc_vps_download.py, is a more advanced enumerator that issues WebDAV PROPFIND requests with Depth: 1 to recursively map account file trees, tightens its delay to 1.5-3.5 seconds, and logs every retrieval to /root/oc_download.log. Using this access the operator staged roughly 9 GB of data referenced in a CSV manifest named after the victim's parent ministry; Hunt.io itself recovered 176 files (~372 MB) across five categories spanning reactor-operations records, radiation-safety documentation, strategic/IT planning material, and 130 MB of personnel/PII, plus a KEYS subfolder containing KeePass databases, AxCrypt-encrypted files, and BitLocker recovery keys. A separate 192 MB SQL dump of a ZKTeco BioTime attendance/personnel database, also recovered from the top-level of the same open directory, referenced additional Philippine government science and research organizations.

Against the naval marine-engineering and shipbuilding contractor's WordPress site, the operator exploited CVE-2024-28000, an unauthenticated privilege-escalation flaw (CVSS 9.8) in the LiteSpeed Cache plugin. The flaw lets an attacker who obtains or brute-forces a debug-log hash spoof the plugin's role-simulation feature to impersonate an administrator, then create a new administrator account via the /wp-json/wp/v2/users REST API endpoint. Compiled Go exploit binaries (wp28000, wp28000_cp) and their source (main.go) were found alongside brute_xmlrpc.py, which brute-forced WordPress credentials via XML-RPC wp.getUsersBlogs calls using the rockyou.txt wordlist, and brute_result.txt logging successful hits. Three archives totaling 195 MB -- the full site tree, a database dump, and the media library -- were staged from this intrusion.

The same 31.58.209[.]241 host also served a stage-1 ELF loader (multi_backupd, SHA-256 7447d0d0c34779d4c519823b39bf6ddc16d2b34a226b82ee69da6f5b4a77ad82) and, from port 8090, a Mettle (portable Meterpreter) stage-two payload (stage2_payload.bin, SHA-256 10df3451915ea35bcb17efe121415f24182680e2d07fc09df07ee695072104c1). A Sliver C2 framework installation was also present on the server, though Hunt.io did not directly attribute its use to a specific intrusion step. Additional service fingerprints on the host included a cloned ownCloud login page on port 80, OpenSSH 9.6p1 Ubuntu on port 22, a Python 3.12.3 BaseHTTP responder on port 8080, and a raw TCP listener on port 54329.

Attribution rests on circumstantial but consistent evidence: stolen files were sorted into folders labelled in simplified Chinese (财务/Finance, 辐射安全/Radiation Safety, 核材料账目/Nuclear Material Accounts, IT规划/IT Planning, 系统文档/System Documentation), and script docstrings describe "low-speed download" operations against nuclear-material and radiation-safety documents in Chinese. No named group was attributed. Hunt.io disclosed its findings to CERT-PH under TLP:AMBER, which notified the affected organizations before the embargo lifted on 2026-08-25; Hunt.io published its report on 2026-08-26, assessing with medium confidence that the activity reflects targeted rather than opportunistic collection, given the reactor/naval-specific targeting despite the underlying vulnerabilities being broadly exploitable.

## MITRE ATT&CK

- T1583.003 Acquire Infrastructure: Virtual Private Server
- T1587.001 Develop Capabilities: Malware
- T1587.004 Develop Capabilities: Exploits
- T1608.002 Stage Capabilities: Upload Tool
- T1190 Exploit Public-Facing Application
- T1136.001 Create Account: Local Account
- T1110.001 Brute Force: Password Guessing
- T1213 Data from Information Repositories
- T1074.001 Data Staged: Local Data Staging
- T1560 Archive Collected Data
- T1588.002 Obtain Capabilities: Tool
- T1059.006 Command and Scripting Interpreter: Python
- T1068 Exploitation for Privilege Escalation
- T1552.001 Unsecured Credentials: Credentials In Files
- T1083 File and Directory Discovery
- T1074.002 Data Staged: Remote Data Staging
- T1105 Ingress Tool Transfer
- T1020 Automated Exfiltration
- T1204 User Execution: Malicious File
- T1218 System Binary Proxy Execution: Mshta
- T1071 Application Layer Protocol: Web Protocols

## Sources

- [Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities](https://hunt.io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor)
- [Hackers Exploit ownCloud and WordPress Flaws to Steal Philippine Nuclear and Naval Data](https://cybersecuritynews.com/hackers-exploit-owncloud/)
- [CVE-2023-49105 Detail - NVD](https://nvd.nist.gov/vuln/detail/cve-2023-49105)
- [CVE-2024-28000 Detail - NVD](https://nvd.nist.gov/vuln/detail/cve-2024-28000)
- [Immediate Action Required: Critical Security Updates for ownCloud](https://owncloud.com/blogs/immediate-action-required-critical-security-updates-for-owncloud/)
- [Critical Privilege Escalation in LiteSpeed Cache Plugin](https://patchstack.com/articles/critical-privilege-escalation-in-litespeed-cache-plugin-affecting-5-million-sites/)
- [Over 5,000,000 Site Owners Affected by Critical Privilege Escalation Vulnerability Patched in LiteSpeed Cache Plugin](https://www.wordfence.com/blog/2024/08/over-5000000-site-owners-affected-by-critical-privilege-escalation-vulnerability-patched-in-litespeed-cache-plugin/)
- [ownCloud exploits for CVE-2023-49105 (ambionics)](https://github.com/ambionics/owncloud-exploits)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2172
