A suspected Chinese-speaking threat actor has exploited WordPress vulnerabilities to breach at least 49 organizations across 29 countries. The campaign highlights how compromised websites can serve as entry points for database theft, credential abuse, and broader network intrusions. The attackers utilized the wp2shell chain, known as CVE-2026-63030 and CVE-2026-60137, against vulnerable WordPress installations.

GreyNoise also observed the same actor targeting other technologies, including ZyXEL GS1900 switches, where 996 devices in 48 countries were compromised or had sensitive information exfiltrated. GreyNoise linked the campaign to scans and exploitation of network appliances, developer platforms, Linux systems, and business applications, indicating a broad search for exposed services rather than a single-victim operation.

Defenders should enable multifactor authentication, restrict database access from web servers, monitor unusual administrator creation, and alert on password spraying and unexpected archive downloads. Blocking one address may not stop the actor, but identifying repeated scanning patterns, suspicious webshell requests, and access to configuration files can help defenders detect the intrusion earlier. Here are the indicators of compromise (IoCs): - Hash SHA-256: Backdoor - Hash SHA-256: Backdoor - Hash SHA-256: Backdoor - Domain *.981666.xyz: Command-and-control infrastructure - IP address 74.48.66.73: Staging infrastructure - IP address 104.225.153.141: Command-and-control infrastructure - IP address 172.245.247.21: Exploitation infrastructure - Account name kapibala2: Created by the threat actor - Account name kapibala: Threat actor-associated account