Philippine Nuclear and Naval Targets Hit by Suspected Chinese-Speaking Operator

A suspected Chinese-speaking threat actor breached Philippine nuclear research and naval-related organizations by exploiting known vulnerabilities in internet-facing ownCloud and WordPress systems, stealing sensitive data including nuclear reactor component databases and personnel records, according to Security Affairs and independent research from Hunt.io.

Known Vulnerabilities, High-Value Targets

The intrusions exploited two previously disclosed vulnerabilities — CVE-2023-49105 and CVE-2024-28000 — rather than a novel zero-day, underscoring how unpatched, internet-exposed systems remain a viable entry point into sensitive government and defense-adjacent networks years after fixes became available. Hunt.io researchers linked the activity to infrastructure including an IP address at 31.58.209[.]241, and found that stolen data was organized using Chinese-language folder and file names, including terms corresponding to “Nuclear Material Accounts” and “IT Planning,” along with code comments and docstrings that strongly suggest the operator is a native Chinese speaker or highly fluent in the language.

Intelligence Collection, Not Opportunistic Crime

Researchers characterized the operation as consistent with targeted intelligence collection against high-value defense and scientific institutions rather than financially motivated cybercrime. The theft of nuclear reactor component data and personnel records from two organizations raises particular concern given the sensitivity of nuclear material accounting information, which is typically subject to international safeguards and non-proliferation reporting requirements.

Recommended Response

Security Affairs and Hunt.io both recommend that organizations running ownCloud and WordPress promptly apply available patches, upgrade to supported versions, and enforce strong authentication measures given the continued exploitation of these older, publicly known flaws. The incident adds to a broader pattern of suspected Chinese state-linked operators targeting critical infrastructure and defense-adjacent organizations across the Indo-Pacific region, an area of persistent concern for U.S. and allied cybersecurity agencies monitoring pre-positioning activity ahead of potential regional conflict scenarios.

Comments

One response to “Philippine Nuclear and Naval Targets Hit by Suspected Chinese-Speaking Operator”

  1. […] work altogether. Compliance requirements of this kind sit alongside physical protections for critical infrastructure and defense-linked targets that state-linked threat actors continue to […]

Leave a Reply

Your email address will not be published. Required fields are marked *