NewsTradingSentimentEventsCommunityBriefing
Tech

Chinese Hackers Steal 18,500 Records via Network Switch Flaws

By Tech Desk · · 2 min read
A flat vector illustration of a network switch with multiple ports connected to a server rack in a data center.

A state-linked group compromised 996 devices and accessed government databases using unpatched vulnerabilities in common networking and web technologies.

Key points

  • Attackers stole over 18,500 records, including plaintext passwords, from government and law enforcement databases.
  • 996 ZyXEL network switches were compromised to extract configurations and root-level credentials.
  • The campaign exploited unpatched WordPress and Ubiquiti vulnerabilities detected by GreyNoise sensors.

A Chinese-speaking threat actor has successfully compromised nearly 1,000 network devices and stolen over 18,500 sensitive records from backend databases. The campaign targeted organizations across 29 countries, including small businesses and government agencies, by exploiting known security weaknesses in widely used software and hardware. Researchers identified the activity as part of a broader effort to gather intelligence on high-value entities, with one notable intrusion into an unnamed Western government organization.

The attack chain began with the exploitation of vulnerabilities in the WordPress core component, specifically the wp2shell flaws. Once inside, the actor conducted extensive reconnaissance to understand the internal security landscape before moving laterally. They located credentials for a backend SQL database and used them to spray passwords, eventually gaining access to an internal SQL server. The stolen data included account details, plaintext passwords, and personally identifiable information linked to government and law enforcement agencies.

Exploiting unpatched network hardware

Beyond web applications, the attackers focused on network infrastructure. In mid-August, they exploited a high-severity flaw in ZyXEL GS1900 Smart Managed Switches. This allowed them to compromise 996 devices in 48 countries, extracting device configurations, network maps, and hashed root-level credentials. This access provided a foothold for deeper network infiltration and data exfiltration, demonstrating how physical network components can be a primary entry point for digital espionage.

The group also attempted to chain multiple vulnerabilities in Ubiquiti UniFi OS to achieve remote code execution. These specific flaws were flagged by the US Cybersecurity and Infrastructure Security Agency (CISA) as actively exploited. The reliance on unpatched firmware highlights a significant trade-off for organizations: the convenience of managed network switches often comes with a delayed patch cycle, leaving them vulnerable to targeted attacks.

Detection through global monitoring

The campaign was detected by GreyNoise, a threat intelligence company, through its global network of sensors. Scans and attacks attributed to the adversary originated from the same IP address and were recorded starting in early June 2026. The group is linked to the Red Heron cluster, which has previously exploited critical flaws in self-hosted Git services. GreyNoise noted that not all the vulnerabilities used in this campaign have been added to CISA's catalog of Known Exploited Vulnerabilities, creating a gap in official risk assessments.

Risks of delayed patching

The incident underscores the critical importance of rapid patch management, especially for internet-facing devices. Public exploits for the WordPress vulnerabilities became available in mid-July, and active exploitation began shortly after. Organizations that failed to apply updates within this window were left exposed. The catch is that many smaller entities lack the resources to monitor every security bulletin, making them prime targets for such state-sponsored actors who systematically scan for these gaps.

GreyNoise has shared indicators of compromise, including hashes for backdoors and command-and-control infrastructure, to help defenders identify similar activity. The breach of a Russian state organization in occupied Ukraine, described as a red-on-red compromise, adds a layer of geopolitical complexity. For readers, the stakes are clear: even minor security oversights in common tools can lead to significant data leaks involving sensitive government and personal information.

Based on reporting by BleepingComputer, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories