Chinese-Speaking Actor Breaches Philippine Nuclear and Naval Targets

Chinese-Speaking Actor Breaches Philippine Nuclear and Naval Targets

First seen 31 Aug 2026, 12:53 UTC Securityaffairs.Cohunt.io 77.0

Article Content

Browse articles
ThreatCluster

A suspected Chinese-speaking threat actor has compromised Philippine nuclear and naval organizations by exploiting known vulnerabilities in internet-facing systems. The attack targeted a nuclear research body and a marine engineering company supporting the Philippine Navy, using vulnerabilities in ownCloud and WordPress. Hunt.io discovered the breach after identifying an open directory containing custom Python scripts and logs on a compromised server. Approximately 9 GB of sensitive data was stolen from the nuclear agency, with evidence of a third potential victim. The activity is part of a broader trend of cyber intrusions against Philippine critical infrastructure amid rising tensions in the South China Sea. The attack was reported to CERT-PH, which coordinated notifications to the affected organizations. The incident highlights the ongoing threat posed by state-sponsored actors in the region.

Key Points: • Over 14,000 Dahua cameras compromised in related incidents. • Attackers exploited known vulnerabilities in ownCloud (CVE-2024-28000) and WordPress (CVE-2023-49105). • Approximately 9 GB of sensitive data stolen from a Philippine nuclear research agency.

Timeline

2023-11-21
CVE-2023-49105 published
A vulnerability in WordPress was disclosed, later added to CISA KEV for active exploitation.
hunt.io
2024-08-21
CVE-2024-28000 published
A vulnerability in ownCloud was disclosed, allowing unauthorized access to files.
hunt.io
2026-08-13
Breach discovered by Hunt.io
Hunt.io identified an open directory on a compromised server, revealing intrusion tools and logs.
hunt.io
2026-08-25
Responsible disclosure completed
Hunt.io held publication until CERT-PH notified affected organizations of the breach.
hunt.io
2026-08-27
CVE-2023-49105 added to CISA KEV
CISA confirmed active exploitation of the WordPress vulnerability in the wild.
hunt.io