Chinese-Speaking Threat Actor Steals Data via ZyXEL and WordPress Exploits
Share
A Chinese-speaking threat actor has compromised 996 devices and exfiltrated more than 18,500 records by exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress installations.
The campaign involved targeting backend databases to steal sensitive information, with the attacker leveraging multiple technology stacks to gain unauthorised access to various systems.
Technical Exploitation and Impact
The intrusion utilised flaws within the ZyXEL GS1900 series of Smart Managed Switches. By targeting these networking devices, the threat actor was able to facilitate further movement into protected environments.
In addition to network hardware exploits, the actor utilised vulnerabilities in WordPress to gain a foothold in web-based systems. This multi-vector approach allowed for the systematic targeting of backend databases, leading to the theft of large volumes of data.
The scale of the breach, involving nearly 1,000 devices, suggests a coordinated effort to target organisations holding sensitive information. While the specific types of government data stolen have not been fully disclosed, the actor’s focus on backend databases indicates a high level of intent to access core information repositories.
Administrators of ZyXEL GS1900 switches and WordPress-based platforms should immediately ensure that all hardware firmware and software plugins are updated to the latest secure versions to mitigate the risk of exploitation.




Leave a Reply