The breach was part of a wider campaign targeting vulnerable WordPress installations worldwide. The activity from May 7, 2026 onward to a single malicious cyber actor believed to be a Chinese-speaking operator, possibly active in the UTC+8 time zone.
The actor is suspected to be the same group, or linked to, the “Red Heron” campaign previously reported by Acronis.
GreyNoise said the threat actor began exploiting WordPress sites around July 20 using the wp2shell exploit chain, involving CVE-2026-63030 and CVE-2026-60137.
The campaign successfully compromised at least 49 organizations across 29 countries, mainly affecting government and small-business targets.
WordPress Breach Exposes Passwords
The government intrusion began on July 22, when the attacker used the WordPress exploit chain to deploy a custom web shell on the targeted server. Within minutes, the actor extracted the WordPress user table, stealing 13 administrator accounts.
The attackers then accessed the WordPress administration panel and created a new account designed to appear legitimate. They altered its registration date to make it blend in with the victim’s existing account history.
After gaining access, the threat actor uploaded a custom information-gathering plugin and used the web shell to inspect the Windows-based server environment.
The attacker searched for security tools, local users, network services, database software, WordPress configuration files, and security settings.
GreyNoise observed the actor attempting to bypass Microsoft’s Antimalware Scan Interface (AMSI), elevate privileges, create local administrator accounts, and access registry data.
.webp)
The actor also searched readable files for cleartext credentials and found working credentials for a backend SQL database. The stolen credentials were then used in password-spraying attempts against internal systems.
The attacker successfully accessed the SQL server, extracted data in bulk, compressed the stolen files into ZIP archives, and placed them in a web-accessible location before downloading them.
At least 18,566 records containing accounts, plaintext passwords, and personally identifiable information were exfiltrated. GreyNoise said the attacker continued password-spraying activity after the theft in an apparent attempt to expand access inside the organization.
The WordPress activity was only one component of a broader campaign. GreyNoise observed the actor scanning or attacking products from Ubiquiti, Gitea, FlowiseAI, Nuclio, SENAITE LIMS, Proxmox, and ZyXEL.
.webp)
The group also exploited CVE-2026-7273 in ZyXEL GS1900 Smart Managed Switches beginning around August 17. GreyNoise said this was the first publicly documented exploitation of the flaw in the wild.
The campaign compromised 996 switches across 48 countries and collected device configurations, network information, and hashed root credentials.
Notably, 564 of the affected ZyXEL devices still used factory-default credentials, increasing the attacker’s ability to access and collect sensitive device data.
Indicators of Compromise
| IOC Type | Indicator | Description |
|---|---|---|
| SHA-256 | 0e81d80b40eaacbf6cb1e817fb1824c30a824af5cb4faca4aa9b03fd506d480f | Malicious backdoor |
| SHA-256 | 0f6e757e82c4d91df5bd249f775b9970b59dee42cc0dfe40f879d77fc16821c6 | Malicious back |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team
The post Hackers Breach Government WordPress Site and Steal 18,566 Records With Plaintext Passwords appeared first on Cyber Security News.