Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti UniFi OS Flaws to Steal Government Data

Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains (TL-2026-2619), also tracked as Open Season on Kapibala, is a critical-severity advanced persistent threat campaign scored CVSS 10, first published 2026-09-22. It is attributed to Kapibala (China) with medium confidence, affects WordPress WordPress Core (wp2shell chain), references 12 CVEs (CVE-2026-63030, CVE-2026-60137, CVE-2026-7273), maps to 17 MITRE ATT&CK techniques (T1014, T1021.004, T1027), and is covered by 9 detection rules and 22 indicators of compromise.

Key facts for TL-2026-2619

Threat ID
TL-2026-2619
Also known as
Open Season on Kapibala
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
APT
First published
2026-09-22
Last reviewed
2026-09-22
Attribution
Kapibala
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
government administration, police - law enforcement, defense, electioninfrastructure, energy, aerospace, telecoms, smallbusiness, research, industrial
Target regions
North America, Europe, Asia-Pacific, 005 - South America, 151 - Eastern Europe, Middle East
Detection rules
9
Indicators of compromise
22

Malware and tooling in Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains

Malware and tooling: JITTERLY, SIXZUT, FOFA, GodPotato, PyArmor

A Chinese-speaking threat actor GreyNoise tracks as "Kapibala" — assessed as the same as, or related to, the Acronis-documented "Red Heron" group — has exploited a rolling chain of at least 12 CVEs across WordPress, Zyxel GS1900 switches, Ubiquiti UniFi OS, Gitea, and five other products since May 2026, compromising 996 Zyxel devices across 48 countries and breaching 49+ organizations across 29 countries. The campaign's most severe confirmed intrusion stole 18,566 records — including plaintext passwords and PII — from a Western government/law-enforcement WordPress deployment in a single ~5-hour operation.

How Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains works

GreyNoise Intelligence's Global Observation Grid (GOG) has tracked a single Chinese-speaking operator, internally labeled "Kapibala" after a self-created backdoor account (kapibala2), conducting an escalating multi-vector exploitation campaign since at least May 7, 2026. The actor sequentially weaponized newly disclosed and n-day CVEs across nine distinct products: PAN-OS GlobalProtect reconnaissance (June 11), Ubiquiti UniFi OS improper-access-control flaws CVE-2026-34908/34909/34910 (June 12, CVSS up to 10.0), FlowiseAI's hardcoded-JWT-secret authentication bypass CVE-2026-56271 (July 13), a WordPress Core "wp2shell" chain combining a REST API batch-endpoint routing-confusion bug (CVE-2026-63030) with a SQL injection flaw (CVE-2026-60137) to achieve RCE (July 20), the well-known Linux "Dirty Pipe" privilege-escalation bug CVE-2022-0847 (July 23), a Gitea diffpatch/three-way-merge hook-injection RCE CVE-2026-60004 (July 30), a Nuclio dashboard unauthenticated OS command injection CVE-2026-79756 (August 13), a Zyxel GS1900 series stack-based buffer overflow CVE-2026-7273 (August 17), a SENAITE.CORE LIMS unauthenticated RCE via missing authorization plus unsafe eval() CVE-2026-54569 (August 27), and a 2023 Proxmox VE authentication-bypass flaw CVE-2023-54391 that skips password verification via the tfa-challenge parameter (September 3).

The campaign's most damaging confirmed intrusion targeted a Western government/law-enforcement organization's WordPress site on July 22, 2026. Within roughly five hours the actor deployed the wp2shell exploit chain to upload a webshell, dumped the WordPress user table (13 accounts), created a backdoor local administrator account (kapibala2) with a backdated timestamp, uploaded reconnaissance tooling, and attempted at least 17 distinct AMSI-bypass script variations to defeat Windows Defender/AMSI — variations GreyNoise assesses were likely LLM-generated based on superficial, functionally-identical renaming patterns. The actor then escalated privileges using the GodPotato token-impersonation/theft tool to steal a SYSTEM token, harvested cleartext credentials from accessible .asp/.config files, staged stolen data as ZIP archives in web-accessible paths, exfiltrated the archive, and pivoted internally: password-spraying stolen credentials against SMB shares and an internal SQL server, from which 18,566+ records (accounts, plaintext passwords, and PII tied to government and law-enforcement agencies) were bulk-extracted. The wp2shell chain separately compromised at least 49 organizations across 29 countries — predominantly small businesses and government bodies, including a Russian state entity inside Russia-occupied Ukraine (a "red-on-red" compromise).

Starting August 17, 2026, the same actor pivoted to mass-exploiting CVE-2026-7273, an unauthenticated LAN-based stack buffer overflow in the CGI program of Zyxel GS1900 Smart Managed Switches (firmware 2.10 through 2.90 across the GS1900-8/8HP/10HP/16/24/24E/24EP/24HPv2/48/48HPv2 line), using a Python exploit script obfuscated with the commercial tool PyArmor 6.7.5. This compromised 996 devices across 48 countries (led by Italy, the US, Taiwan, France, South Korea, and the Netherlands), extracting device configurations, network information, and hashed root credentials; 564 of the 996 victims were still running factory-default credentials. CISA added CVE-2026-7273 to its Known Exploited Vulnerabilities catalog on September 21, 2026, one day before public disclosure.

GreyNoise assesses Kapibala is "the same as, or related to" Red Heron, a Chinese-speaking actor separately documented by Acronis's Threat Research Unit exploiting the same Gitea CVE-2026-60004 in a parallel campaign against 1,386 scanned Gitea instances (with a dedicated dataset of 477 Taiwan-based systems), confirming compromises in Canada, Argentina, Taiwan, the US, Qatar, and Sri Lanka across defense, election, energy, aerospace, telecom, government, public-safety, and research sectors. That intrusion progressed from source-code theft to a newly documented Linux implant, JITTERLY (a C++ ELF backdoor with 30+ post-exploitation commands including shell/PTY access, chunked file transfer, and SOCKS/TCP tunneling, communicating over AES-128-GCM-encrypted msgpack to s2.981666.xyz:8082), paired with SIXZUT, a 49KB LD_PRELOAD rootkit (deployed as libglthread.so.2 via /etc/ld.so.preload) that hides files, processes, and network connections by hooking getdents/open/stat and netlink calls. GreyNoise's own C2 findings for Kapibala (the domain 981666.xyz and its subdomain p3.981666.xyz, used as a Redis-based C2 channel on port 6379) share the same root domain as Acronis's JITTERLY C2 (s2.981666.xyz), directly linking the two tracked clusters' infrastructure.

Both research teams assess the actor operates from a PRC-linked context with moderate-to-low confidence: extensive Simplified Chinese-language comments and reconnaissance/classification metadata (with Taiwan consistently labeled as a Chinese region rather than a separate country), use of the China-based FOFA scanning platform, apparent UTC+8 working hours, and targeting priorities (defense, election infrastructure, energy, aerospace) that align with Chinese state collection interests. No confirmed link to a previously tracked, named APT group has been established; "Kapibala" and "Red Heron" remain researcher-assigned cluster names for overlapping infrastructure and tradecraft.

MITRE ATT&CK techniques used in TL-2026-2619

Defense Evasion

T1014 Rootkit; T1027 Obfuscated Files or Information; T1574.006 Dynamic Linker Hijacking

Lateral Movement

T1021.004 SSH

Command and Control

T1071.001 Web Protocols; T1572 Protocol Tunneling

Discovery

T1082 System Information Discovery; T1518.001 Security Software Discovery

Credential Access

T1110.003 Password Spraying; T1552.001 Credentials In Files

Privilege Escalation

T1134.001 Token Impersonation/Theft

Persistence

T1136.001 Local Account; T1505.003 Web Shell

Initial Access

T1190 Exploit Public-Facing Application

Collection

T1213 Data from Information Repositories; T1560 Archive Collected Data

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains

  • WordPress — WordPress Core (wp2shell chain)
    Vulnerable versions: 6.9.0-6.9.4; 7.0.0-7.0.1
    Fixed in: Update to the vendor release addressing CVE-2026-63030/CVE-2026-60137, added to CISA KEV 2026-07-21
  • Zyxel — GS1900 Smart Managed Switches
    Vulnerable versions: GS1900-8 <=2.90(AAHH.1)C0; GS1900-8HP <=2.90(AAHI.1)C0; GS1900-10HP <=2.90(AAZI.1)C0; GS1900-16 <=2.90(AAHJ.1)C0; GS1900-24 <=2.90(AAHL.1)C0; GS1900-24E <=2.90(AAHK.1)C0; GS1900-24EP <=2.90(ABTO.1)C0; GS1900-24HPv2 <=2.90(ABTP.1)C0; GS1900-48 <=2.90(AAHN.1)C0; GS1900-48HPv2 <=2.90(ABTQ.1)C0
    Fixed in: Zyxel firmware release June 2026, added to CISA KEV 2026-09-21
  • Ubiquiti Inc — UniFi OS
    Vulnerable versions: UniFi OS Server <5.0.8; UDM/UDM-Pro/UDM-SE/UDM-Pro-Max <5.1.12; UDM-Beast <5.1.11; Dream Router/Dream Router 7/Dream Router 5G <5.1.12; UniFi Express 7 <5.1.12; Network Video Recorder series <5.1.12; Cloud Key Plus/CloudKey/CloudKey Enterprise <5.1.12; Cloud Gateway series <5.1.12; UNAS storage devices <5.1.10
    Fixed in: 5.0.8 / 5.1.10 / 5.1.11 / 5.1.12 per device line
  • Gitea — Gitea
    Vulnerable versions: 1.17-1.27.0
    Fixed in: 1.27.1
  • Linux Kernel — Linux Kernel (Dirty Pipe)
    Vulnerable versions: 5.8 through 5.16.10 (approx.)
    Fixed in: 5.16.11 / 5.15.25 / 5.10.102
  • FlowiseAI — Flowise (npm package, enterprise passport auth middleware)
    Vulnerable versions: 0 through 3.0.13
    Fixed in: 3.1.0
  • Nuclio — Nuclio serverless dashboard
    Vulnerable versions: <1.17.4
    Fixed in: 1.17.4
  • SENAITE — SENAITE.CORE LIMS
    Vulnerable versions: 2.0.0 through 2.6.0
    Fixed in: Version beyond 2.6.0 addressing CVE-2026-54569
  • Proxmox — Proxmox VE (libpve-access-control)
    Vulnerable versions: 7.0-7.4; 8.0 before libpve-access-control 8.0.4
    Fixed in: libpve-access-control 8.0.4

Remediation for Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains

Patches

  • WordPress Core update beyond 7.0.1
  • Zyxel GS1900 firmware update (June 2026 release)
  • Ubiquiti UniFi OS Server 5.0.8+ / UDM family 5.1.12+ / UDM-Beast 5.1.11+ / UNAS 5.1.10+
  • Gitea 1.27.1+
  • Nuclio 1.17.4+
  • Flowise 3.1.0+
  • SENAITE.CORE beyond 2.6.0
  • Proxmox VE libpve-access-control 8.0.4+
  • Linux kernel 5.16.11 / 5.15.25 / 5.10.102 or later (Dirty Pipe)

Immediate actions

  • Patch WordPress Core to a version beyond 7.0.1 to remediate the wp2shell chain (CVE-2026-63030, CVE-2026-60137)
  • Update all Zyxel GS1900 series switches to the vendor firmware released June 2026 that fixes CVE-2026-7273; disable LAN-exposed web/CGI management where not required
  • Patch Ubiquiti UniFi OS and all affected controllers/gateways/NVRs to the versions fixing CVE-2026-34908/34909/34910
  • Upgrade Gitea to 1.27.1+ (CVE-2026-60004), Nuclio to 1.17.4+ (CVE-2026-79756), Flowise to 3.1.0+ (CVE-2026-56271), SENAITE.CORE beyond 2.6.0 (CVE-2026-54569), and Proxmox VE libpve-access-control to 8.0.4+ (CVE-2023-54391)
  • Apply the Dirty Pipe (CVE-2022-0847) kernel fix on any Linux hosts still running kernel 5.8-5.16.10
  • Hunt for the backdoor account name pattern "kapibala"/"kapibala2" and any unexpected local administrator accounts with backdated creation timestamps
  • Hunt for /etc/ld.so.preload tampering, the file libglthread.so.2, and the config artifact .ld_aux_cahe on internet-facing Linux hosts
  • Force credential rotation for any WordPress, Gitea, or database accounts exposed on a system running an affected product
  • Block C2 indicators: 981666.xyz and subdomains, 74.48.66.73, 104.225.153.141, 172.245.247.21, 72.11.138.109, xcyoibfhuufz.com

Workarounds

  • Restrict LAN access to Zyxel GS1900 CGI management interface pending firmware update
  • Disable the Proxmox two-factor challenge endpoint or enforce TFA for all accounts as a stopgap for CVE-2023-54391
  • Block outbound access to identified C2 domains/IPs at the perimeter

Longer-term hardening

  • Replace factory-default credentials on all network appliances; Zyxel found 564 of 996 compromised switches still using defaults
  • Segment management interfaces of network switches and IoT/edge devices away from general LAN access
  • Deploy EDR/AMSI-aware tooling capable of detecting scripted AMSI-bypass variants and GodPotato-style token impersonation
  • Monitor for LD_PRELOAD-based persistence and rootkit techniques on internet-facing Linux servers
  • Establish a vulnerability management SLA for internet-facing CMS, Git hosting, and low-code/AI-orchestration platforms given the actor's rapid n-day weaponization pattern

CVEs associated with Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains

CVE-2026-63030, CVE-2026-60137, CVE-2026-7273, CVE-2026-34908, CVE-2026-34909, CVE-2026-34910, CVE-2026-56271, CVE-2022-0847, CVE-2026-60004, CVE-2026-79756, CVE-2026-54569, CVE-2023-54391

Weaknesses (CWE) in Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains

CWE-436, CWE-89, CWE-121, CWE-284, CWE-321, CWE-78, CWE-95, CWE-862, CWE-304

Timeline of Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains

  • GreyNoise Global Observation Grid begins attributing scanning/exploitation activity to a single Chinese-speaking operator later named "Kapibala".
  • Actor begins exploiting Ubiquiti UniFi OS improper-access-control flaws CVE-2026-34908/34909/34910 (CVSS up to 10.0).
  • CVE-2026-34908/34909/34910 added to the CISA Known Exploited Vulnerabilities catalog.
  • Actor begins exploiting FlowiseAI's hardcoded-JWT-secret authentication bypass, CVE-2026-56271.
  • Actor begins the "wp2shell" WordPress exploit chain (CVE-2026-63030 routing confusion + CVE-2026-60137 SQL injection) to achieve remote code execution.
  • CVE-2026-63030 and CVE-2026-60137 added to the CISA Known Exploited Vulnerabilities catalog.
  • A Western government/law-enforcement WordPress deployment is fully compromised in a ~5-hour operation: webshell upload, user-table dump, backdoor account creation, 17 AMSI-bypass attempts, GodPotato token theft, credential harvesting, and bulk exfiltration of 18,566+ records.
  • Actor observed exploiting the Linux "Dirty Pipe" privilege-escalation vulnerability, CVE-2022-0847.
  • Gitea ships version 1.27.1, patching the diffpatch/three-way-merge hook-injection RCE later tracked as CVE-2026-60004.
  • Actor (overlapping with Acronis-tracked "Red Heron") begins exploiting Gitea CVE-2026-60004, deploying the JITTERLY implant and SIXZUT LD_PRELOAD rootkit.
  • Actor begins exploiting the unauthenticated Nuclio dashboard OS command injection, CVE-2026-79756.
  • Actor begins mass-exploiting Zyxel GS1900 switches via CVE-2026-7273 using a PyArmor-obfuscated Python exploit; campaign eventually compromises 996 devices across 48 countries.
  • CVE-2026-60004 (Gitea) added to the CISA Known Exploited Vulnerabilities catalog.
  • Actor begins exploiting the 2023 Proxmox VE authentication-bypass flaw CVE-2023-54391 via the tfa-challenge parameter.
  • CVE-2026-7273 added to the CISA Known Exploited Vulnerabilities catalog, one day before public disclosure.
  • GreyNoise publishes "Open Season on Kapibala," and BleepingComputer/Help Net Security/CyberInsider report the campaign publicly.

Sources cited for Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains

More in apt

Detection coverage for TL-2026-2619

As of 2026-09-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2619 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats