Hunt.io Details Intrusions Targeting Philippine Nuclear and Naval-Linked Organizations

· Original article ↗

Summary

Hunt.io found evidence of intrusions against a Philippine nuclear research body and a naval-linked marine engineering company, involving ownCloud and WordPress vulnerabilities, data theft, and a suspected Chinese-speaking operator.

Key points

  • Hunt.io found an exposed directory containing custom scripts, logs, offensive tools, and stolen data; it reported that the directory was still accessible at publication.
  • Scripts used ownCloud CVE-2023-49105 to retrieve files over WebDAV without credentials when the signing secret was empty. Recovered material totaled about 372 MB; an attacker-created CSV referenced roughly 9 GB exfiltrated.
  • Stolen nuclear-agency files included reactor and radiation-safety records, employee personal information, travel documents, and credential stores, including BitLocker keys and a KeePass database.
  • At a naval-linked marine engineering company, a custom exploit for LiteSpeed Cache CVE-2024-28000 created an administrator account; a separate XML-RPC password-guessing attempt also succeeded. A WordPress site archive, database dump, and media library were staged for exfiltration.
  • Hunt.io assessed targeted collection with medium confidence, citing Chinese-language code and organized data collection, but did not attribute the activity to a named threat actor.
  • Researchers separately identified a likely unrelated EtherHiding/ClickFix compromise on the WordPress site and found 174 IP addresses hosting pages with matching loader indicators.
  • Recommended measures include upgrading ownCloud and LiteSpeed Cache, setting a strong ownCloud signing key, restricting XML-RPC, and monitoring for suspicious WebDAV activity.

Article Details

Attack Vectors
  • The operator used CVE-2023-49105 to construct pre-signed WebDAV requests with an empty signing secret, impersonate known ownCloud users, enumerate directories with PROPFIND, and retrieve files without supplying credentials.
  • A custom exploit used CVE-2024-28000 in LiteSpeed Cache to create a WordPress administrator account through the REST API.
  • A separate script guessed credentials through WordPress XML-RPC using the rockyou.txt wordlist; its output recorded a successful credential pair.
  • An attacker-created CSV noted confirmed access through an IDOR in a project management application, indicating a possible third compromise.
  • A possibly unrelated compromise of the same WordPress site injected a NoChain loader that displayed a fake Google verification page and directed visitors to download a VBS dropper.
Defensive Notes
  • Upgrade ownCloud to 10.13.3 or later, or apply its specific patch, and configure a strong signing key for pre-signed URLs.
  • Patch LiteSpeed Cache to version 6.4 or later.
  • Disable WordPress XML-RPC where unnecessary, or restrict /xmlrpc.php to trusted sources.
  • Use strong, unique administrator passwords and multi-factor authentication.
  • Monitor WebDAV activity for PROPFIND enumeration from a single source and file retrieval across multiple accounts.

Indicators of compromise

TypeIndicatorContext
IPV431[.]58[.]209[.]241Operator-controlled server that exposed staged tools, stolen data, and an open directory; the loader also retrieved a second-stage payload from this IP.
SHA25610df3451915ea35bcb17efe121415f24182680e2d07fc09df07ee695072104c1Hash of the retrieved Mettle stage-2 payload, stage2_payload.bin.
SHA2567447d0d0c34779d4c519823b39bf6ddc16d2b34a226b82ee69da6f5b4a77ad82Hash of the multi_backupd stage-1 ELF loader found on the operator's server.

MITRE ATT&CK

T1074.001 · Local Data StagingRetrieved ownCloud files were organized in per-account directories, while WordPress material was placed in an exfil folder on the operator's server.T1083 · File and Directory DiscoveryAn ownCloud collection script used WebDAV PROPFIND requests with Depth: 1 to enumerate directories.T1110.001 · Password GuessingThe operator guessed passwords for the WordPress admin account through XML-RPC using rockyou.txt; an output file recorded a successful credential pair.T1136.001 · Local AccountThe LiteSpeed Cache exploit created a new WordPress administrator account through the REST API.T1190 · Exploit Public-Facing ApplicationThe intrusions exploited CVE-2023-49105 in an internet-facing ownCloud instance and CVE-2024-28000 in a LiteSpeed-Cache-enabled WordPress site.T1213 · Data from Information RepositoriesThe operator retrieved documents from the nuclear agency's ownCloud repository across multiple staff accounts.T1560 · Archive Collected DataThree archives containing the WordPress site tree, database dump, and media library were staged under exfil.T1583.003 · Virtual Private ServerThe article maps the operator's staging server, hosted by CGI Global Limited in Amsterdam, to VPS infrastructure acquisition.T1587.001 · MalwareThe operator created custom Python scripts for ownCloud pre-signed URL abuse and WordPress XML-RPC credential guessing.T1587.004 · ExploitsThe operator built a Go exploit for CVE-2024-28000 that reproduced PHP mt_rand() output to search for a valid security hash.T1608.002 · Upload ToolSliver, Metasploit, Mettle, and a compiled WordPress exploit were staged on the operator's server; the article says recovered logs do not tie the three frameworks to the intrusions.

CVE

Malware

Vendors

Products

Tools

Countries

Industries

Related Articles