Suspected Chinese-Speaking Operator Targeted Philippine Nuclear Agency, Naval Contractor
A suspected Chinese-speaking cyber operator targeted a Philippine nuclear research organization and a marine engineering and shipbuilding company serving the Philippine Navy, according to a new threat intelligence report published by Hunt.io on August 26.
The investigation began after Hunt.io identified an exposed server containing hacking tools, attack scripts, logs and data allegedly stolen from two Philippine organizations. The researchers said the server was discovered on August 13 and contained more than 1,300 files totaling about 1.17 GB.
One of the primary targets was an internet-facing ownCloud system operated by a Philippine nuclear research body. Hunt.io said the attacker exploited a known ownCloud vulnerability, CVE-2023-49105, which can allow unauthorized access to files when a vulnerable installation has an improperly configured signing secret.
The recovered material included documents related to nuclear operations and safety, research reactor components, historical fuel inventories, radiation-safety documentation, strategic and IT planning, employee personal information and credential-related files. Hunt.io also found evidence indicating that approximately 9 GB of material may have been exfiltrated, although only around 372 MB of the stolen files were recovered from the exposed staging directories.
The investigation also uncovered a second Philippine victim: a marine engineering and shipbuilding company that provides services to the Philippine Navy. According to Hunt.io, the operator compromised the company's WordPress website using multiple techniques, including exploitation of CVE-2024-28000 in the LiteSpeed Cache plugin and credential brute-forcing through WordPress XML-RPC.
The attacker allegedly obtained administrator access and extracted a complete copy of the website, including its files, media library and database. A separate 192 MB database dump from a ZKTeco BioTime attendance and personnel system was also found on the server, containing information associated with several Philippine science and research organizations.
Hunt.io said the operator's use of Simplified Chinese in code comments, documentation, logs and folders used to organize stolen information strongly suggests that the individual or group behind the activity is Chinese-speaking. However, the researchers did not attribute the activity to a specific threat actor or group. Hunt.io assessed with medium confidence that the campaign represented targeted collection rather than opportunistic attacks, citing the deliberate selection and organization of stolen data.
The report also identified evidence of a possible third victim involving project-management infrastructure connected to the same ministry, including references to unauthorized access and approximately 38 credential sets. Hunt.io cautioned that the available evidence does not establish the full scope of the activity.
Hunt.io disclosed its findings to CERT-PH under TLP:AMBER and said publication was delayed following responsible disclosure while CERT-PH coordinated notification with the affected organizations.
The incident highlights the continuing risk faced by Philippine government, research and defense-adjacent organizations from internet-facing systems that remain vulnerable to publicly documented security flaws. Hunt.io recommended patching affected ownCloud and WordPress components, securing administrator accounts with strong passwords and multifactor authentication, and monitoring for suspicious WebDAV and XML-RPC activity.
Hunt.io emphasized that the investigation does not establish whether the suspected operator was state-sponsored, contracted or acting independently. The available evidence instead points to a technically capable actor conducting deliberate collection against organizations with sensitive nuclear, government and defense-related information.
Other contents