1. Basic Information
- Title: Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation
- Source: GreyNoise
- Published Date: 2026-09-21
- Collected Date: 2026-09-23T08:14:06+09:00
- Original Source: GreyNoise
- Severity: critical
- Severity Justification: GreyNoise has confirmed an incident where attackers breached a Western government organization's database via a WordPress compromise, stealing at least 18,566 records containing account information, plaintext passwords, and personally identifiable information associated with government and law-enforcement agencies. The same threat actor also exploited CVE-2026-7273 to steal configurations, hashed root credentials, and network information from 996 Zyxel GS1900 switches across 48 countries.
- Related Source: BleepingComputer: Reporting on Scope of Impact
- Related Source: BleepingComputer: CISA KEV Addition Reporting
- Related Malware: Custom Kapibala-related WordPress web shells
- Related Threat Actor: Kapibala-tracked actor; same as or related to Red Heron according to GreyNoise, but not formally attributed
- CVEs: CVE-2026-63030, CVE-2026-60137, CVE-2026-7273
- Target Products and Services: WordPress, Zyxel GS1900
2. Summary in One Sentence
A campaign where a suspected Chinese-speaking threat actor moved from a WordPress wp2shell vulnerability chain to web shell deployment, credential theft, and internal SQL database intrusion, while separately exploiting CVE-2026-7273 in Zyxel GS1900 devices.
3. Attack Flow
Path A: Intrusion from WordPress to Internal SQL Database
- The attacker compromises a public WordPress site using the wp2shell chain, combining CVE-2026-63030 and CVE-2026-60137.
- They deploy a custom web shell and search for WordPress administrator accounts,
wp-config.php, and credentials on the host. - Using the stolen credentials, they perform a password spray against the internal SQL database and successfully gain access.
- They extract and compress data using custom tools, temporarily saving it in a web-accessible location.
- They steal at least 18,566 records containing account information, plaintext passwords, and personally identifiable information associated with government and law-enforcement agencies.
Path B: Configuration and Credential Theft from Zyxel GS1900
- The attacker targets attacker-reachable Zyxel GS1900 web management interfaces vulnerable to CVE-2026-7273.
- The attacker exploits the CGI stack-based buffer overflow to execute OS commands without authentication, downloads a collector script via TFTP, and stages the collected data for retrieval.
- They exfiltrate configurations, hashed root credentials, and network information from 996 devices across 48 countries.
4. Attacker Location and Execution Point
- Attackers continuously scanned and compromised multiple public services and network devices from shared external infrastructure.
- Post-exploitation activities on WordPress occurred on the target host via web shells, while attacks on Zyxel devices took place through device management and web processing interfaces.
5. Visibility for Victims and Administrators
Victims
- Breaches can extend to backend credentials and databases without any clear anomalies appearing on the website frontend.
Administrators
- Indicators include unknown PHP files or plugins, PowerShell execution, access to SAM, registry, or
wp-config.php, a high volume of failed SMB/SQL authentication attempts followed by successful access, and bulk retrieval of Zyxel configurations.
6. Success and Failure Conditions
Success Conditions
- The target WordPress site or Zyxel GS1900 is unpatched and reachable from the attacker (The attacker can reach the GS1900 web management interface, which Zyxel describes as a LAN-based attack surface).
- The WordPress host can reach credential-containing files or the internal database.
- Stolen credentials can be reused for internal SQL authentication.
Failure and Prevention Conditions
- Patching target CVEs and restricting management interfaces to trusted networks.
- Minimizing privileges and communication paths from the web server to the internal database, and avoiding credential reuse.
- Continuously monitoring changes to web roots, plugins, accounts, and network device configurations.
7. What Happens Upon Success
- WordPress administrator credentials, source code, configuration files, accounts within the internal SQL database, plain-text passwords, and personal information are stolen.
- Zyxel GS1900 configurations, hashed root credentials, and network information are stolen.
- Additional intrusion into internal systems becomes possible using the stolen credentials.
8. Observable Logs
- email: No public evidence indicates email was used in the initial intrusion for this campaign.
- proxy_swg_dns: Detect access to web shells or temporarily saved ZIP files, communication with attack infrastructure, and outbound traffic from Zyxel devices.
-
endpoint_edr: Detect unknown PHP web shells, PowerShell execution, access to SAM, registry, or
wp-config.php, and execution of compression tools. - identity_idp: Detect suspicious WordPress administrator logins, new accounts, modified registration timestamps, and heavy internal SQL logins.
- saas_cloud: If applicable cloud management platforms exist, detect configuration retrieval and management API operations.
- network: Detect vulnerability exploitation against multiple products from the same source, a high volume of failed SMB/SQL authentication attempts followed by successful access, heavy data transfers from databases, and retrieval of switch configurations.
9. Attack Success Determination
Confirmed via Public Information
- Follow-on Compromise Confirmed (WordPress Path): GreyNoise reconstructed the WordPress intrusion from preserved file-modification timestamps and artifacts obtained from adversary infrastructure, covering WordPress compromise, web shell deployment, credential theft, successful internal SQL authentication, and the theft of over 18,566 records.
- Data Theft Confirmed (Zyxel Path): It has been confirmed that CVE-2026-7273 was exploited to steal configurations, hashed root credentials, and network information from 996 switches across 48 countries.
Internal Evaluation Criteria
- Verify web shell deployment, credential access, internal SQL authentication, and data extraction, compression, and exfiltration using separate evidence.
- Verify crafted HTTP requests to the CGI interface, command execution, outbound TFTP traffic, collector-script execution, creation of /home/web/tmp/info.txt, and subsequent data retrieval.
10. Investigation Playbook
Trigger
- Triggered by attacks targeting wp2shell CVEs, unknown PHP files, added WordPress administrators, heavy SQL logins, and configuration retrieval from devices targeted by CVE-2026-7273.
Initial Verification
- Check product versions and patch status for WordPress, plugins, and Zyxel GS1900, as well as external accessibility.
- Cross-reference internal logs with sources, file hashes, domains, and timestamps published by GreyNoise.
Endpoints
- Preserve web roots, plugins, web shells, PowerShell history, compressed files, credential access, and deletion artifacts.
Authentication and Cloud
- Review WordPress administrators, new accounts, SQL authentication, network device management authentication, and configuration retrieval history.
Subsequent Activity
- Track internal system authentication using stolen credentials, additional data access, persistence, and external exfiltration.
Containment
- Patch target CVEs, remove web shells and unauthorized accounts, and rotate compromised credentials.
- Restrict access to Zyxel management interfaces, block unnecessary outbound TFTP traffic, limit web server communication to internal databases, and block known attack infrastructure.
Decision Categories
- Assess vulnerability exploitation, web shell deployment, credential theft, internal authentication success, data theft, and network device compromise separately.
11. Defense and Detection Ideas
Single Events
- Detect the creation of unknown PHP files in web roots, added WordPress administrators, access to SAM, registry, or
wp-config.php, and high-volume SQL logins with high priority. - Detect suspicious management requests and bulk configuration retrieval targeting Zyxel GS1900.
Timeline Correlation
- Correlate WordPress vulnerability exploitation, web shells, credential discovery, SQL password spraying, and data extraction, compression, and external retrieval into a single timeline.
Hunting Perspectives
- Hunt across environments for Kapibala-related web shells, hashes, domains, administrators with modified registration timestamps, web-accessible temporary ZIP files, and devices vulnerable to CVE-2026-7273.
Log Gaps
- Without web server process/file monitoring or SQL auditing, connecting initial intrusion to data theft is impossible. If device-side logs expire quickly, forward them externally.
Priority Countermeasures
- Prioritize patching CVE-2026-7273 (added to CISA KEV) and wp2shell-related CVEs.
- Implement least privilege from the web tier to databases, separate credentials, and restrict network device management access.
12. Facts, Inference, and Hypothesis
Facts
- Attackers compromised at least 49 organizations using the wp2shell chain.
- At least 18,566 records containing account information, plaintext passwords, and personally identifiable information associated with government and law-enforcement agencies were stolen from a Western government organization.
- CVE-2026-7273 was exploited to steal configurations, hashed root credentials, and network information from 996 Zyxel GS1900 switches across 48 countries.
- CVE-2026-7273 was added to the CISA KEV catalog by September 22, 2026.
Inference
- Compromise of a public-facing web server can become an internal database breach when readable configuration files contain reusable credentials and the web tier is permitted to reach backend systems.
Hypothesis
- GreyNoise notes that surface-level code iterations strongly indicate LLM generation, but no direct evidence of LLM usage has been published.
- A connection to Red Heron is suggested as a possibility, but formal attribution is not confirmed.
13. MITRE ATT&CK Mapping
- T1190 Exploit Public-Facing Application (Confidence: high) — Exploiting vulnerabilities in public-facing WordPress and Zyxel interfaces.
- T1505.003 Server Software Component: Web Shell (Confidence: high) — Deploying custom web shells following WordPress compromise.
- T1003.002 Security Account Manager (Confidence: Medium) — The attacker attempted to dump SAM and registry data.
- T1110.003 Password Spraying (Confidence: High) — Stolen credentials were tested against an internal server through password spraying.
- T1552.001 Unsecured Credentials: Credentials In Files (Confidence: High) — Cleartext credentials were searched for and recovered from readable configuration files.
- T1213 Data from Information Repositories (Confidence: high) — Extracting large volumes of information from internal SQL databases.
14. Unknowns and Further Investigation
- The threat actor's formal attribution and relationship with Red Heron remain unconfirmed.
- The full scope of victim organizations, complete range of exfiltrated data, and subsequent use of stolen credentials have not been published.
15. Impact on SOCs and Organizations
This should not be treated merely as patching a single product vulnerability; it must be handled as a breach path spanning public web servers, network devices, credentials, and internal databases. Alongside patching target CVEs, investigate web shells, unauthorized accounts, SQL authentication, and data extraction/exfiltration as a single coordinated incident.
16. Summary by Role
- For SOCs: Track WordPress vulnerability exploitation, web shells, credential discovery, SQL authentication, and data theft, alongside the active exploitation of Zyxel CVE-2026-7273, as separate attack paths.
- For Administrators: Prioritize patching target CVEs, minimize permissions and communication between the web tier and databases, and restrict network device management interfaces.
- For Users: Backend breaches can occur even when websites appear normal; promptly follow any instructions from administrators to change credentials.
Top comments (0)