Interestana
Home/News/Chinese Hackers Exploit ZyXEL, WordPress Flaws for Data Theft
BleepingComputer3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Chinese Hackers Exploit ZyXEL, WordPress Flaws for Data Theft

A Chinese-speaking threat actor has been actively exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to pilfer sensitive data from 996 compromised devices and over 18,500 records residing in backend databases. The campaign, identified by security researchers, targets governmental entities, indicating a sophisticated and persistent effort to gain unauthorized access to confidential information. The threat actor leverages a combination of known and potentially zero-day vulnerabilities to achieve their objectives, demonstrating a multifaceted approach to cyber intrusion.

The exploitation chain begins with the compromise of ZyXEL GS1900 Smart Managed Switches. These devices, commonly used in enterprise and government networks for network management and traffic control, present a critical entry point when their security is breached. The specific vulnerability exploited in the ZyXEL devices has not been publicly disclosed, but its successful exploitation allows the attackers to establish a foothold within the network infrastructure. Following the initial compromise of the switch, the threat actor then proceeds to target WordPress installations. WordPress, a widely used content management system, powers a significant portion of the internet, including many government websites. Vulnerabilities in WordPress plugins, themes, or the core software itself can be exploited to gain further access to sensitive data stored within the associated databases.

The stolen data encompasses a broad range of sensitive information, including government documents, personal identifiable information (PII) of citizens, and potentially classified intelligence. The sheer volume of compromised records, exceeding 18,500, underscores the scale and impact of this cyber espionage operation. The threat actor's ability to maintain access and exfiltrate data over an extended period suggests a high level of technical proficiency and operational security. Researchers have observed the use of custom malware and sophisticated evasion techniques to remain undetected by conventional security measures. The motive behind this operation is believed to be intelligence gathering and espionage on behalf of a state-sponsored entity, consistent with the tactics, techniques, and procedures (TTPs) associated with Chinese-speaking advanced persistent threats (APTs).

Security advisories have been issued to alert organizations utilizing ZyXEL GS1900 switches and WordPress platforms to the heightened risk. Recommendations include immediate patching of all known vulnerabilities, rigorous monitoring of network traffic for anomalous activity, and the implementation of robust security controls, such as multi-factor authentication and intrusion detection systems. The ongoing nature of this threat necessitates continuous vigilance and proactive security measures to mitigate the risk of further data breaches. The incident highlights the persistent challenges in securing critical infrastructure and sensitive data against well-resourced and determined adversaries in the current geopolitical landscape.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next