Hunt.io identified an exposed staging server containing custom tooling, logs, and stolen data linked to intrusions at a Philippine nuclear-research agency and a defense-adjacent marine engineering company serving the Philippine Navy. The operator allegedly exploited ownCloud CVE-2023-49105 to forge pre-signed WebDAV URLs, impersonate users, and collect nuclear operations, personnel, strategic-planning, and credential data; available records indicate roughly 9 GB of data was exfiltrated.
The naval contractor’s WordPress environment was separately compromised through LiteSpeed Cache CVE-2024-28000 and XML-RPC credential brute forcing, after which the actor staged a full website archive and database dump. Researchers assessed with medium confidence that the activity represented targeted collection aligned with Chinese interests amid South China Sea tensions, but did not attribute it to a named group. A separate EtherHiding/NoChain ClickFix infection was also found on the WordPress site, with no evidence tying it to the intrusion operator.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
CISA added ownCloud Server CVE-2023-49105 to its Known Exploited Vulnerabilities catalog, confirming the critical authentication-bypass flaw had been exploited in the wild. The addition followed reporting linking the vulnerability's exploitation to theft of sensitive data from a Philippine nuclear research organization.
Hunt.io disclosed its findings to CERT-PH under TLP:AMBER and delayed public reporting until August 25, 2026, to enable notification of the affected Philippine organizations.
Hunt.io identified an open directory at 31.58.209[.]241:8000, hosted in Amsterdam and served with Python SimpleHTTP. The server contained 1,310 files across 86 directories, including intrusion tooling, logs, and data linked to the Philippine nuclear-research and naval-contractor intrusions.
Reporting associated the activity with the domains fine-work-team.com, timelevel12.com, and snake.zooparkko.com; IP address 31.58.209.241; two SHA-256 hashes; and Ethereum smart-contract address 0x58460d0b3d4d6b03761c89120393c0c676676496.
Researchers identified an active EtherHiding/NoChain compromise on the naval contractor's WordPress site that delivered a fake Google verification ClickFix lure through an Ethereum smart contract. They assessed the activity as potentially unrelated to the suspected Chinese-speaking intrusion operator.
The operator compromised a Philippine marine engineering and shipbuilding company serving the Philippine Navy using LiteSpeed Cache CVE-2024-28000 and XML-RPC credential brute forcing. The actor gained WordPress administrator access and staged archives containing the site installation, media library, and SQL database with password hashes and secret keys.
An attacker-created CSV indicated that roughly 9 GB of data was exfiltrated from the nuclear agency, while 176 retrieved files totaling about 372 MB remained on the staging server. The CSV also recorded confirmed access to a project-management application associated with the agency's parent ministry.
A suspected Chinese-speaking operator exploited ownCloud CVE-2023-49105 to forge pre-signed WebDAV URLs, impersonate accounts, enumerate directories, and retrieve files from a Philippine nuclear research body. The collected material included reactor and fuel records, radiation-safety and incident data, strategic documents, employee PII, and credential-related files.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
8 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcecommunity.gurucul.com
Open sourcereddit.com
Open sourcehunt.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.