GreyNoise has tracked a single, prolific attacker since June 2026 that opportunistically exploits a wide
range of internet-facing technologies, and in one intrusion stole more than 18,000 sensitive records
from a western government. The actor used a custom WordPress exploit chain to breach the
government’s site, planted a hidden web shell and a disguised administrator account, escalated to full
control, and exfiltrated 18,566 records that included accounts, plaintext passwords and personal
information tied to law-enforcement and government agencies. The same operator, a suspected
Chinese speaker who appears to build tools with the help of an AI language model, also compromised
at least 49 WordPress organisations across 29 countries and 996 ZyXEL network switches worldwide
using a brand-new exploit. Because the campaign is broad, fast-moving and driven by exploitation of
unpatched, exposed services, organisations should patch the affected technologies, stamp out
plaintext credentials, and hunt for the indicators below.
1. Campaign Overview
Using its Global Observation Grid, GreyNoise tracked a single malicious cyber actor (MCA) from early June 2026 that
used one IP address to scan and exploit a wide variety of technologies. GreyNoise is withholding the exact IP for victim
safety and will publish it later. The actor is a suspected Chinese speaker operating in UTC+8, based on the operational
timeline and copious Chinese-language code comments, and GreyNoise suspects the MCA used a large language model
to build its custom tools, citing rapid iteration and code artefacts. Over a few months the MCA exploited technologies
including WordPress, Ubiquiti UniFi OS, ZyXEL switches, FlowiseAI, Gitea, Nuclio, SENAITE LIMS, Proxmox VE and the
Linux kernel (DirtyPipe). The findings were published by GreyNoise on 21 September 2026.
2. Targeting
The campaign is opportunistic and global. WordPress exploitation succeeded against at least 49 organisations
across 29 countries, primarily small business and government, including a red-on-red compromise of a Russian
state entity. The standout intrusion targeted an unnamed western government, from which the actor stole 18,566
records including accounts, plaintext passwords and personally identifiable information associated with law
enforcement and government agencies. Separately, the MCA exfiltrated configurations, hashed root credentials
and network information from 996 ZyXEL GS1900 switches across 48 countries, of which 564 still used factory
default credentials. Any organisation running the affected, internet-exposed technologies should consider itself a
potential target.
3. Attack Chain
The reconstructed WordPress intrusion against the government victim (22 July 2026) illustrates the actor’s end-to-end
tradecraft.
- Initial Access WORDPRESS EXPLOIT CHAIN: The MCA used a custom wp2shell exploit chain (CVE-2026-63030 and CVE-2026-60137) to compromise the site, deploy a web shell, and dump the WordPress user table, stealing 13 administrator accounts.
- Persistence BLENDED ADMIN ACCOUNT: It logged into wp-admin, created a rogue administrator masquerading as a legitimate @victimdomain account, and backdated the account’s registration to 2025 to blend into the site’s history, then uploaded a custom enumeration plugin.
- Privilege Escalation AMSI BYPASS & TOKEN THEFT: The actor ran at least 17 script variations to bypass Microsoft’s Antimalware Scan Interface, escalate privileges via token impersonation and theft, create a local administrator, and dump registry hives.
- Credential Access CLEARTEXT HUNTING: A custom tool searched readable files for cleartext credentials, yielding usable findings including credentials to a backend SQL database.
- Collection & Exfiltration SQL DATABASE THEFT: Using password spraying, the MCA reached an internal SQL database, bulk-extracted its contents, and downloaded at least 18,566 records; loot was packed into a ZIP via PowerShell in a web-reachable path and retrieved.
4. Tooling & Other Exploitation
The actor relies on custom, likely LLM-assisted tooling and a broad exploitation portfolio.
- LLM-assisted custom tooling: GreyNoise suspects the MCA generated its custom tools and scripts with a large language model, based on rapid iteration, non-meaningful code changes between versions, and code comments, many in Chinese.
- WordPress wp2shell chain: A custom chain for CVE-2026-63030 and CVE-2026-60137 deploys a web shell and enumeration plugin, dumps user tables, and creates disguised, backdated administrator accounts to persist.
- ZyXEL GS1900 pre-auth RCE (CVE-2026-7273): A heavily PyArmor-obfuscated Python exploit for a novel, first-in the-wild pre-auth RCE (not on CISA KEV at publication) fetched a collector script over TFTP and exfiltrated configs, hashed root credentials and network data from 996 switches in 48 countries.
- Broad multi-CVE exploitation: Beyond WordPress and ZyXEL, the MCA targeted UniFi OS (CVE-2026 34908/34909/34910, delivering a backdoor), FlowiseAI (CVE-2026-56271), Gitea (CVE-2026-60004), Nuclio (CVE 2026-79756), SENAITE LIMS (CVE-2026-54569), Proxmox VE (CVE-2023-54391) and the Linux kernel DirtyPipe flaw (CVE-2022-0847).
5. Indicators of Compromise (IOCs)
| Type | Indicator |
| SHA256 | 0e81d80b40eaacbf6cb1e817b1824c30a824af5cb4fac4aa9803fd506d480f (backdoor) |
| SHA256 | 0f6e757e82c4d91df5db249f775b9970b59dee42ccdfe40f879d77fc16821c6 (backdoor) |
| SHA256 | 2ff2945b13a4cd0e9a65c85af29ea1539e162a516466c0de682dbf9f8a4000b1 (UniFi backdoor) |
| DOMAIN | *.981666[.]xyz (C2) |
| IP | 104.225.153[.]141 (C2) |
| IP | 74.48.66[.]73 (staging) |
| IP | 172.245.247[.]21 (exploitation) |
| FILENAME | kapibala (attacker-created account) |
| FILENAME | kapibala2 (attacker-created account) |
6. Recommendations
- Patch the exploited stack, prioritising internet-facing services: WordPress (CVE-2026-63030, CVE-2026 60137) and ZyXEL GS1900 (CVE-2026-7273), plus UniFi OS (CVE-2026-34908/34909/34910), FlowiseAI (CVE-2026-56271), Gitea (CVE-2026-60004), Nuclio (CVE-2026-79756), SENAITE LIMS (CVE-2026 54569), Proxmox VE (CVE-2023-54391) and the Linux kernel DirtyPipe flaw (CVE-2022-0847).
- Eliminate plaintext credentials: hash and salt stored passwords, remove cleartext secrets from files and configuration, and rotate anything exposed. The government breach succeeded largely because plaintext passwords and database credentials were sitting in readable files.
- Hunt WordPress compromise: review for unexpected administrator accounts (especially backdated user_registered dates or ones mimicking your own domain), unknown plugins, web shells in web-reachablepaths, and user-table dumps; enforce MFA on wp-admin and restrict it by IP.
- Detect the post-exploitation tradecraft: AMSI-bypass attempts, token-impersonation privilege escalation, registry-hive or SAM dumps, password spraying against internal SQL databases, and staged ZIP archives placed in web-reachable directories.
- Harden network appliances: patch ZyXEL GS1900 switches, change factory-default credentials (564 victims still used defaults), disable internet-facing management, and check for TFTP-delivered collector scripts and configuration or credential exfiltration.
- Block the IOCs at their respective controls (the backdoor hashes, the C2, staging and exploitation IPs, and *.981666[.]xyz), and alert on the creation of accounts named ‘kapibala’ or ‘kapibala2’.
7. Sources
- https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-government-records-wo
rdpress-exploitation
Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn
No related posts found.