Critical ownCloud and WordPress Flaws Exploited to Steal Philippine Naval Data
Key Takeaways A suspected Chinese-speaking threat actor leveraged known vulnerabilities in ownCloud and WordPress to exfiltrate sensitive data from a Philippine nuclear research agency and a naval...
Key Takeaways
- A suspected Chinese-speaking threat actor leveraged known vulnerabilities in ownCloud and WordPress to exfiltrate sensitive data from a Philippine nuclear research agency and a naval contractor.
- The stolen information includes critical nuclear reactor data, staff records, financial documents, and a complete archive of the naval contractor’s website.
- The attacks exploited CVE-2023-49105 in ownCloud (CVSS score 9.8, critical) and CVE-2024-28000 in the LiteSpeed Cache WordPress plugin.
- The incident highlights the severe risks posed by unpatched, internet-facing systems, particularly those holding national security-related data.
- Both ownCloud and WordPress users should apply immediate patches and implement robust security measures to prevent similar breaches.
A sophisticated cyber operation, attributed to a suspected Chinese-speaking individual or group, has successfully compromised a Philippine nuclear research facility and a marine engineering firm contracted by the Philippine Navy. The attackers exploited critical, known vulnerabilities in ownCloud and WordPress platforms to extract a significant volume of sensitive data, underscoring the persistent threat posed by unpatched systems.
Table Of Content
This intrusion came to light following the discovery of an openly accessible server containing the attacker’s tools, logs of data transfers, and a portion of the exfiltrated files. The compromised data reportedly encompasses highly sensitive information, including documents related to nuclear reactor operations, personnel records, strategic planning materials, encrypted credential stores, and a full backup of the naval contractor’s WordPress site. Further details are available in this report.
Security researchers at Hunt.io discovered the exposed server on August 13 and subsequently linked the scripts found on it to the attacks targeting the two Philippine entities. While Hunt.io did not name a specific threat group, Hunt.io said in a report that the evidence points to a Chinese-speaking operator.
The scale of the data exfiltration is considerable. An inventory found on the server indicated approximately 9 GB of data was stolen from the nuclear agency. Researchers were able to directly recover 176 files, totaling about 372 MB, from five separate staging folders. This discrepancy suggests that the publicly accessible server likely contained only a fraction of the total data collected by the attackers.
Exploiting ownCloud and WordPress Vulnerabilities
Nuclear Agency Compromised via ownCloud Flaw
The attackers gained unauthorized access to the nuclear agency’s self-hosted ownCloud service by exploiting CVE-2023-49105, a critical authentication bypass vulnerability (CVSS score 9.8). This flaw exists in the platform’s pre-signed link feature. On ownCloud installations where a signing key is not configured, attackers can craft valid WebDAV requests for known usernames without needing to provide a password.
The attackers utilized five custom Python scripts to systematically download files, account by account. These scripts also leveraged WebDAV directory requests to map out folder structures and incorporated brief, random pauses between downloads. This methodical approach was likely designed to evade detection by making the data transfer appear less suspicious and more like routine activity.
The exfiltrated data from the nuclear agency included highly sensitive information such as databases related to research-reactor core components, fuel inventory records, radiation safety protocols, incident reports, staff resumes, travel documents, and financial disclosures. Furthermore, investigators found a KeePass database, AxCrypt-encrypted files, and a PDF containing a BitLocker recovery key, all of which could facilitate future access or decrypt additional sensitive information. The stolen files were meticulously organized into folders labeled in simplified Chinese, categorized by areas such as finance, radiation safety, nuclear material accounts, and IT planning.
Naval Contractor Breached Through WordPress Vulnerability
The second victim, a Philippine marine engineering and shipbuilding company with ties to naval services, was compromised through a vulnerability in its WordPress installation. The attackers exploited CVE-2024-28000, a flaw in the LiteSpeed Cache plugin affecting versions prior to 6.4. This allowed them to create a new administrator account via the WordPress REST API after successfully deriving the plugin’s security hash.
Analysis of logs revealed that the exploit process ran for nearly three hours and 45 minutes before a valid hash was found and the rogue administrator account was created. In parallel, the attackers targeted the site’s XML-RPC interface, attempting password guesses against the administrative account, eventually recording a successful credential pair in a separate output file.
The attackers staged three archives from the naval contractor’s site, totaling 195 MB. These included the complete WordPress installation, a database dump, and the media library. Such comprehensive data can expose critical information like password hashes, plugin configurations, and site secrets. The establishment of a rogue administrator account also provides a persistent backdoor for future unauthorized access. This incident highlights the ongoing risk of rogue WordPress admin accounts.
Separately, researchers identified an active EtherHiding-style compromise on the same WordPress site, though evidence did not link it to the current operator. This additional compromise utilized a fake verification page to deliver malware and a service worker for persistence, illustrating how a single compromised site can host multiple, unrelated threats. This aligns with broader trends where <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/286837fb-df95-49a7-9c7c-d4dba34898d5/Hackers-Exploit-ownCloud-and-WordPress-Flaws-to-Steal-Philippine-Nuclear-and-Naval-Data.pdf?AWSAccessKeyId=ASIA2F3EMEYE6ZOFWJPY&Signature=GOvV86daqyCtGKlIj7%2BkfjmAfY
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.