started · updated
Philippine nuclear and naval targets breached by suspected Chinese-speaking hackers
Suspected Chinese-speaking operators have breached a Philippine nuclear research organization and a marine engineering company that supports the Philippine Navy. The attackers exploited known vulnerabilities in internet-facing ownCloud and WordPress systems to steal sensitive information.
Researchers at Hunt.io discovered an exposed server in Amsterdam containing custom Python scripts, exfiltration logs, and offensive tooling. The investigation revealed that approximately 9 GB of material was stolen from the nuclear agency, including nuclear material records, research reactor data, personnel files, and encryption key material. The breach of the nuclear agency involved exploiting CVE-2023-49105, a flaw in ownCloud where a lack of a configured signing secret allowed attackers to generate forged WebDAV requests to retrieve files.
The incident was disclosed to CERT-PH under the TLP:AMBER standard, with publication delayed to allow for coordinated notifications to the affected organizations. The cyber activity occurs amid ongoing tensions in the South China Sea and reported patterns of cyberattacks against Philippine government and critical infrastructure targets.
Entities
CERT-PH · CGI Global Limited · Hunt.io · Philippine nuclear research organization