Hunt.io Details Intrusions Targeting Philippine Nuclear and Naval-Linked Organizations

Summary
Hunt.io found evidence of intrusions against a Philippine nuclear research body and a naval-linked marine engineering company, involving ownCloud and WordPress vulnerabilities, data theft, and a suspected Chinese-speaking operator.
Key points
- Hunt.io found an exposed directory containing custom scripts, logs, offensive tools, and stolen data; it reported that the directory was still accessible at publication.
- Scripts used ownCloud CVE-2023-49105 to retrieve files over WebDAV without credentials when the signing secret was empty. Recovered material totaled about 372 MB; an attacker-created CSV referenced roughly 9 GB exfiltrated.
- Stolen nuclear-agency files included reactor and radiation-safety records, employee personal information, travel documents, and credential stores, including BitLocker keys and a KeePass database.
- At a naval-linked marine engineering company, a custom exploit for LiteSpeed Cache CVE-2024-28000 created an administrator account; a separate XML-RPC password-guessing attempt also succeeded. A WordPress site archive, database dump, and media library were staged for exfiltration.
- Hunt.io assessed targeted collection with medium confidence, citing Chinese-language code and organized data collection, but did not attribute the activity to a named threat actor.
- Researchers separately identified a likely unrelated EtherHiding/ClickFix compromise on the WordPress site and found 174 IP addresses hosting pages with matching loader indicators.
- Recommended measures include upgrading ownCloud and LiteSpeed Cache, setting a strong ownCloud signing key, restricting XML-RPC, and monitoring for suspicious WebDAV activity.
Article Details
- Attack Vectors
- The operator used CVE-2023-49105 to construct pre-signed WebDAV requests with an empty signing secret, impersonate known ownCloud users, enumerate directories with PROPFIND, and retrieve files without supplying credentials.
- A custom exploit used CVE-2024-28000 in LiteSpeed Cache to create a WordPress administrator account through the REST API.
- A separate script guessed credentials through WordPress XML-RPC using the rockyou.txt wordlist; its output recorded a successful credential pair.
- An attacker-created CSV noted confirmed access through an IDOR in a project management application, indicating a possible third compromise.
- A possibly unrelated compromise of the same WordPress site injected a NoChain loader that displayed a fake Google verification page and directed visitors to download a VBS dropper.
- Defensive Notes
- Upgrade ownCloud to 10.13.3 or later, or apply its specific patch, and configure a strong signing key for pre-signed URLs.
- Patch LiteSpeed Cache to version 6.4 or later.
- Disable WordPress XML-RPC where unnecessary, or restrict /xmlrpc.php to trusted sources.
- Use strong, unique administrator passwords and multi-factor authentication.
- Monitor WebDAV activity for PROPFIND enumeration from a single source and file retrieval across multiple accounts.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 31[.]58[.]209[.]241 | Operator-controlled server that exposed staged tools, stolen data, and an open directory; the loader also retrieved a second-stage payload from this IP. |
| SHA256 | 10df3451915ea35bcb17efe121415f24182680e2d07fc09df07ee695072104c1 | Hash of the retrieved Mettle stage-2 payload, stage2_payload.bin. |
| SHA256 | 7447d0d0c34779d4c519823b39bf6ddc16d2b34a226b82ee69da6f5b4a77ad82 | Hash of the multi_backupd stage-1 ELF loader found on the operator's server. |
MITRE ATT&CK
T1074.001 · Local Data StagingRetrieved ownCloud files were organized in per-account directories, while WordPress material was placed in an exfil folder on the operator's server.T1083 · File and Directory DiscoveryAn ownCloud collection script used WebDAV PROPFIND requests with Depth: 1 to enumerate directories.T1110.001 · Password GuessingThe operator guessed passwords for the WordPress admin account through XML-RPC using rockyou.txt; an output file recorded a successful credential pair.T1136.001 · Local AccountThe LiteSpeed Cache exploit created a new WordPress administrator account through the REST API.T1190 · Exploit Public-Facing ApplicationThe intrusions exploited CVE-2023-49105 in an internet-facing ownCloud instance and CVE-2024-28000 in a LiteSpeed-Cache-enabled WordPress site.T1213 · Data from Information RepositoriesThe operator retrieved documents from the nuclear agency's ownCloud repository across multiple staff accounts.T1560 · Archive Collected DataThree archives containing the WordPress site tree, database dump, and media library were staged under exfil.T1583.003 · Virtual Private ServerThe article maps the operator's staging server, hosted by CGI Global Limited in Amsterdam, to VPS infrastructure acquisition.T1587.001 · MalwareThe operator created custom Python scripts for ownCloud pre-signed URL abuse and WordPress XML-RPC credential guessing.T1587.004 · ExploitsThe operator built a Go exploit for CVE-2024-28000 that reproduced PHP mt_rand() output to search for a valid security hash.T1608.002 · Upload ToolSliver, Metasploit, Mettle, and a compiled WordPress exploit were staged on the operator's server; the article says recovered logs do not tie the three frameworks to the intrusions.
CVE
Malware
Vendors
CGI Global LimitedHunt.io identified the open directory on August 13, 2026 at 31.58.209[.]241:8000, served via Python's built-in SimpleHTTP module. The server, located in Amsterdam, is registered to CGI Global Limited (AS56971).ownCloudsecurity tooling, and exfiltrated data from two Philippine organizations. The scripts targeted an ownCloud instance operated by a nuclear research body, using pre-signed URLs generated with an empty signingZKTecoA 192 MB SQL dump from a ZKTeco BioTime attendance and personnel database, recovered from the same server, referenced multiple related Philippine science and research organizations, indicating a possible focus on
Products
AxCryptRetrieved material included nuclear-material account records, a research reactor core-component database, employee PII, and credentials stores: BitLocker keys, KeePass, and AxCrypt.BitLockerRetrieved material included nuclear-material account records, a research reactor core-component database, employee PII, and credentials stores: BitLocker keys, KeePass, and AxCrypt.KeePassRetrieved material included nuclear-material account records, a research reactor core-component database, employee PII, and credentials stores: BitLocker keys, KeePass, and AxCrypt.LiteSpeed CacheCVE-2024-28000 is an unauthenticated privilege escalation vulnerability in the LiteSpeed Cache WordPress plugin, disclosed in August 2024, and affecting versions prior to 6.4. The plugin generates a security hash from aownCloudsecurity tooling, and exfiltrated data from two Philippine organizations. The scripts targeted an ownCloud instance operated by a nuclear research body, using pre-signed URLs generated with an empty signingWordPressfor the unauthenticated retrieval of files over WebDAV. A separate intrusion was observed exploiting a WordPress site operated by a Philippine marine engineering and shipbuilding company that provides services to theZKTeco BioTimeA 192 MB SQL dump from a ZKTeco BioTime attendance and personnel database, recovered from the same server, referenced multiple related Philippine science and research organizations, indicating a possible focus on
Tools
Hunt.io Attack CaptureOn August 13, 2026, Hunt.io Attack Capture identified an open directory on the host 31.58.209[.]241. The server staged custom Python scripts, per-file transfer logs, open-source offensive security tooling, andHuntSQLUsing identifiers from the loader code including the smart contract address, we created a simple HuntSQL query to determine the prevalence of this attack across other compromised servers:MetasploitMettlePortable, cross-platform Meterpreter implementation designed for embedded and constrained environments, distributed alongside Metasploit.Mettleanalysis, the loader connects over TCP to the same IP on port 8090 and pulls a Mettle stage-2 payload, which we retrieved (see IOCs).NoChainabove, and none of the evidence reviewed links the two together. The code contains references to "nochain-demo-frame," and an additional script described below.Sliver
Countries
Industries
DefenseReported cyber intrusion activity by suspected Chinese actors against Philippine government, defense, and critical infrastructure organizations over the past several years has increased with ongoing tensions in theGovernmentReported cyber intrusion activity by suspected Chinese actors against Philippine government, defense, and critical infrastructure organizations over the past several years has increased with ongoing tensions in theMarine engineering and shipbuildingA separate intrusion was observed exploiting a WordPress site operated by a Philippine marine engineering and shipbuilding company that provides services to the Philippine Navy.Nuclear researchdata from two Philippine organizations. The scripts targeted an ownCloud instance operated by a nuclear research body, using pre-signed URLs generated with an empty signing secret, which allowed for the