A suspected Chinese-speaking operator broke into a Philippine nuclear research body and a navy-supporting marine engineering firm using well-known vulnerabilities, and left the evidence on an exposed server that researchers found by accident. CISA has since added the primary bug, CVE-2023-49105 (CVSS 9.8), to its Known Exploited Vulnerabilities catalog.
The trail started with an open directory on host 31.58.209[.]241, a Python SimpleHTTP server left exposed with no authentication. Inside sat custom scripts, transfer logs, offensive tooling including Sliver, Metasploit and Mettle, and stolen data from both organizations. The nuclear body’s internet-facing ownCloud service fell to the WebDAV authentication bypass in CVE-2023-49105, which lets an attacker who knows a valid username make authenticated WebDAV requests without a password when no signing key is configured. Five custom Python scripts implemented the technique, some with directory enumeration and download logging. A separate intrusion hit the marine engineering company through CVE-2024-28000, a privilege-escalation flaw in the LiteSpeed Cache WordPress plugin that lets attackers create an admin account without authentication. XML-RPC password testing against the admin account also succeeded using rockyou.txt.
What was taken matters beyond the two victims. The haul included reactor component databases, fuel inventories, radiation-safety documents, staff records, passports and financial disclosures. A recovered CSV references roughly 9 GB of exfiltrated data, far more than the 372 MB on the exposed server. Hunt.io briefed CERT-PH under TLP:AMBER and delayed publication until August 25 so victims could be notified. The intrusion surfaces amid sustained South China Sea tensions, with a broader pattern of suspected Chinese cyber activity aimed at Philippine government, defense and critical-infrastructure targets.
