Threat Intelligence

Suspected Chinese actor targets Philippine nuclear and naval entities using known vulnerabilities

Plain code with the word "cyberattack" in red.

A suspected Chinese-speaking operator has targeted a Philippine nuclear research body and a marine engineering company supporting the Philippine Navy, exploiting well-known vulnerabilities in internet-facing systems. The activity was uncovered after Hunt.io found an exposed server containing attack scripts, logs, and data stolen from the two organizations, with further coverage provided by Security Affairs.

The attacker exploited CVE-2023-49105, an authentication-bypass flaw in ownCloud, to gain access to the nuclear research body's systems. This allowed for unauthenticated retrieval of files, including databases on nuclear reactor components, fuel inventories, and radiation safety documents. Additionally, a Philippine marine engineering company supporting the Navy was compromised by exploiting CVE-2024-28000, a privilege-escalation flaw in the LiteSpeed Cache WordPress plugin, enabling the attacker to create an administrator account without authentication. The stolen data also included strategic plans, IT documents, and personal information from Philippine officials.

The exposed server contained evidence of the intrusions, including custom Python scripts, logs written in Simplified Chinese, and various tools. While the language suggests a Chinese-speaking operator, no direct link to a specific government or threat group has been confirmed. The incident highlights the continued risk posed by unpatched, known vulnerabilities to critical infrastructure and defense targets.

Source: Security Affairs

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds