Suspected Chinese-speaking hackers exploited known vulnerabilities to steal sensitive data from a Philippine nuclear research organization and a marine engineering company serving the Philippine Navy.
Researchers at Hunt.io discovered an exposed attacker server on August 13, 2026, containing custom exploit scripts, stolen files, logs, and offensive tools.
The activity comes amid heightened South China Sea tensions and continued cyber espionage targeting Philippine government, defense, research, and infrastructure organizations.
The attackers targeted an internet-facing ownCloud server operated by a Philippine nuclear research body.
They exploited CVE-2023-49105, a critical ownCloud authentication bypass affecting vulnerable versions that use an empty pre-signed URL signing secret.
Philippine Nuclear Data Stolen
Using five custom Python scripts, the operators impersonated valid ownCloud users and downloaded files through the WebDAV interface without needing account passwords.
The scripts also used random delays between downloads, likely to reduce suspicious traffic patterns and avoid detection.
Recovered data included nuclear-material account records, research reactor core-component databases, radiation safety documents, safety manuals, strategic and IT plans, and employee records.
![Hunt.io IP intelligence data for 31.58.209[.]241 hosted on CGI Global Limited exposing ports 22, 8000, and 54329 (Source: hunt.io)](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKX3EnkRJGptplXvpwy1UWQ3OKCz5mN3HFY32fEdU5rlrx0wC6u3QtHOKEl22CkAI8uMo3TSAZ1DCLcC8Ltq_oT2jru43ePs3Prj8uqGMWyvQNv8PVXnWom8cYx8_pOhcSPqvTFo6eZakFe3HGUjjVsuF3hF2x4-AgfQeu_tO7oOvoJsgxDSoQ8zsZ72QM/s1999/Suspected+Chinese+figure+1.webp)
The stolen material also included résumés, passport-related files, foreign travel records, financial disclosure forms, and training documents.
Researchers found credential-related material among the files, including BitLocker recovery keys, a KeePass database, and AxCrypt-encrypted files.
A recovered spreadsheet also referenced approximately 9 GB of data allegedly taken from the nuclear agency, suggesting the exposed server contained only part of the stolen material.
The attackers organized files into folders with Simplified Chinese names, including labels for finance, radiation safety, nuclear-material accounts, and IT planning.
Chinese-language comments, logs, and docstrings within the scripts indicate that the operator was likely a Chinese speaker.
A separate 192 MB database dump from ZKTeco BioTime, a personnel and attendance management platform, contained records connected to Philippine science and research organizations.

Such data could help attackers identify personnel, badge assignments, departments, and possible targets for future social engineering or cyber operations.
The same server also contained evidence of a separate compromise involving a Philippine marine engineering and shipbuilding company that provides services to the Philippine Navy.
The attackers exploited CVE-2024-28000, a privilege-escalation flaw in the LiteSpeed Cache WordPress plugin. The vulnerability allowed them to generate a valid security hash, create a new administrator account, and obtain unauthorized access to the company’s WordPress site.
They also used an XML-RPC password-brute-forcing script against the site’s administrator account. Logs indicated that this second method successfully identified valid credentials, Hunt.io said.
Indicators of Compromise
| Indicator | Type | Context |
|---|---|---|
31.58.209[.]241:8000 | IP address / HTTP server | Exposed Python SimpleHTTP open directory used to stage tools, logs, and stolen data |
31.58.209[.]241:8090 | IP address / TCP | Custom multi_backupd loader connected to this port to retrieve its second-stage pay |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN