At a Glance
| Attribute | Details |
|---|---|
| Actor or Group | Suspected Chinese cyber actor (associated with Red Heron) |
| Activity Type | Web exploit chains, webshell deployment, database exfiltration |
| Targets or Victims | Western government agencies, businesses, and network switches |
| Scale | 18,566 records stolen; 996 ZyXEL switches compromised |
| Jurisdiction / Status | Suspected Chinese-nexus actor operating in UTC+8; uncharged |
| Source | GreyNoise Global Observation Grid and Acronis Threat Research |
Executive Summary
An unidentified threat actor breached a western government agency and stole over 18,000 sensitive records. This malicious operation relied on Kapibala WordPress exploitation to compromise servers and exfiltrate database content. Additionally, global sensor telemetry shows that the same intruder compromised nearly one thousand network switches across forty-eight countries.
What Happened
On July 22, 2026, the intruder initiated an automated assault against a western governmental web portal. Specifically, the adversary deployed a two-stage exploit chain combining CVE-2026-63030 and CVE-2026-60137. This chain allowed the attacker to drop a custom web shell named the kapibala plugin.
Immediately after gaining initial webshell access, the intruder dumped the core user table. This rapid maneuver exposed thirteen administrative user accounts. Next, the attacker created a rogue account mimicking a valid domain address. The actor backdated the registration timestamp to 2025 to blend into the site account history.
Furthermore, the intruder uploaded custom assessment plugins to inspect the underlying operating system. As the GreyNoise report states, “The most egregious data theft occurred against an identified western governmental organization involving more than 18,000 sensitive records stolen from its backend database.”
Privilege Escalation and Internal Probing
The threat actor tested seventeen script variations to bypass Microsoft Antimalware Scan Interface detections. Consequently, the adversary stole authentication tokens directly from the Windows logon process. This technique allowed the actor to create a local administrative account named kapibala2.
After establishing administrative control, the intruder searched readable server files for cleartext credentials. This search revealed plaintext passwords for a backend database server. Next, the attacker packaged the stolen application files into a compressed archive on a public web path. The actor quickly downloaded this archive to remote infrastructure.
Soon after, the adversary launched password spraying attacks against internal network servers. The attacker accessed the central database and extracted 18,566 records. These records included plaintext credentials and personal information belonging to government and law enforcement personnel.
Automated Scripting and Language Model Artifacts
Security analysts identified strong evidence indicating that the attacker relied on artificial intelligence assistance. GreyNoise researchers noted, “GreyNoise suspects the MCA used a large language model (LLM) to generate their custom tools due to behavior patterns found in the code, the rapid iteration, and code comments.”
For example, script revisions contained superficial wording changes that provided no functional difference. Furthermore, the source code contained extensive Chinese comments detailing memory-injection routines for the GodPotato privilege tool. These findings suggest the operator used automated prompts to accelerate exploit scripting.
Who Is Behind It
Investigators attribute this intrusion cluster to a suspected Chinese-speaking adversary with moderate confidence. Activity logs indicate that the operator functions primarily during normal business hours in the UTC+8 timezone. In addition, the adversary shares technical infrastructure with known threat campaigns.
According to researchers, “The adversary is the same or related to ‘Red Heron’ reported on by Acronis based on use of the same command and control (C2) domain, malware family, exploitation of Gitea in July, and other tactics, techniques, and procedures (TTPs).” Earlier this year, Acronis documented Red Heron targeting developer platforms. Findings from both cybersecurity firms indicate an aggressive actor focused on data collection.
Impact and Scale
The broader Kapibala WordPress exploitation attacks compromised at least forty-nine organizations across twenty-nine nations. Targeted entities included governmental bodies and commercial businesses in Germany, Colombia, Brazil, and Japan. Interestingly, the attacker also compromised a Russian administrative system operating in occupied Ukraine.
In addition to web applications, the adversary scanned and attacked edge networking infrastructure. On August 17, 2026, the actor targeted ZyXEL GS1900 smart switches using a zero-day exploit for CVE-2026-7273. The attacker used Python scripts protected by legacy PyArmor obfuscation to run remote shell commands.
Consequently, the intruder compromised 996 switches across forty-eight countries, including Italy, the United States, and Taiwan. Shockingly, 564 of those network switches still used factory default login credentials. GreyNoise observed, “GreyNoise observed the MCA scanning and attacking a variety of technologies throughout the last few months.” Telemetry confirms that earlier scans targeted Ubiquiti UniFi network systems and container management platforms.
What Comes Next and Defense Guidance
The ongoing campaign demonstrates that attackers quickly chain web vulnerabilities to penetrate corporate internal networks. Therefore, organizations must update internet-facing content management systems immediately. Administrators should audit user databases to identify newly created accounts with backdated registration stamps.
Additionally, security teams should inspect server file systems for rogue plugin directories containing unusual web shells. Monitoring process execution for suspicious PowerShell commands will help detect token impersonation attempts. Furthermore, network administrators must inspect internal database traffic for abnormal bulk export activity.
Network engineers must also update edge switches and isolate management interfaces from public routing. Default administrative passwords must be changed across all hardware appliances before deployment. For a detailed breakdown of indicators, review the GreyNoise report on Kapibala WordPress exploitation. Rigorous patching schedules and strict access segmentation remain vital defenses against these opportunistic threat actors.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!