Chinese-Speaking Actor Stole Documents via Global Cyberattack
A sustained campaign exploiting web and network hardware vulnerabilities impacted organizations across 29 countries.
Updated on Sept. 21, 2026 in Cybersecurity

Live Poll
Do you feel the risk of cyberattacks on government and local businesses is rising?
Beginning in June 2026, a Chinese-speaking threat actor exfiltrated thousands of government documents by exploiting vulnerabilities in WordPress, Zyxel, and Ubiquiti systems. The campaign, which remains active, compromised 49 organizations globally.
Why it matters
This campaign demonstrates an aggressive strategy of chaining vulnerabilities across disparate hardware and software ecosystems to maintain persistent access. The actor's reliance on custom script automation to evade security protocols marks a sophisticated shift in data-exfiltration tactics.
The actor utilized the wp2shell exploit chain against WordPress and CVE-2026-7273 within Zyxel GS1900 switches. To maintain access, the group deployed 17 distinct scripts designed to bypass the Microsoft Antimalware Scan Interface (AMSI).
The players
Red Heron
A threat actor group identified for its use of automated scripts and LLM-assisted tool development.
CISA
The Cybersecurity and Infrastructure Security Agency, which maintains the authoritative catalog of exploited vulnerabilities.
The details
The attackers targeted vulnerability chains—sequences of flaws used to reach remote code execution—including CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910. Once inside, the actor performed token impersonation, a technique where an attacker assumes the identity of a logged-in user to bypass authentication. Security researchers suspect the group employs large language models (LLMs) to automate the development of these custom hacking tools and scripts.
Timeline
June 12, 2026: The actor attempted to exploit a Ubiquiti vulnerability chain.
June 23, 2026: Ubiquiti vulnerabilities were added to the CISA catalog.
July 20, 2026: A WordPress exploit chain successfully targeted 49 organizations.
September 2026: Red Heron exploited a Gitea vulnerability.
The Tech Race
This campaign follows a pattern established by the CISA Known Exploited Vulnerabilities catalog, which tracks the actor's shift toward high-impact hardware exploits. The rapid adoption of Gitea and Zyxel flaws indicates that threat actors are moving faster than standard patch deployment cycles.
Organizations relying on Zyxel switches, WordPress, or Ubiquiti infrastructure must ensure all firmware and software patches are current to mitigate these specific exploit chains. Users should audit local administrator account lists for unauthorized additions resulting from token impersonation.
The takeaway
The use of 17 distinct scripts to bypass standard endpoint protection signifies that traditional antimalware tools may no longer be sufficient for detecting persistent threats. Security teams should monitor the CISA catalog for further inclusions of CVE-2026-7273 or related hardware flaws.
Further reading
For broader trends in network security and threat intelligence, visit our Cybersecurity section.
Live Poll
Do you feel the risk of cyberattacks on government and local businesses is rising?






