A Chinese-speaking threat actor has engaged in a hacking campaign at least since June, involving the theft of thousands of documents from, at minimum, one Western government, according to a Monday blog post from threat intelligence firm GreyNoise.
The hacker targeted critical vulnerabilities in multiple technologies, including WordPress, Zyxel and Ubiquiti, and is suspected of using a large language model to develop custom tools used in the attacks.
Researchers are still trying to ascertain the adversary’s specific motives beyond gathering large amounts of information.
“The actor is focused on creating access and stealing data,” Andrew Thompson, senior vice president of adversary operations at GreyNoise Intelligence, told Cybersecurity Dive. “The ultimate benefactor is not clear yet.”
Critical flaws targeted
According to GreyNoise, the threat actor has targeted several vulnerabilities in recent months.
On June 12, the hacker tried to exploit a chain of vulnerabilities in Ubiquiti in order to achieve remote code execution. The vulnerabilities included CVE-2026-34908, CVE-2026-34909 and CVE-2026-34910. Those vulnerabilities were added to the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog on June 23.
On July 20, the actor targeted an exploit chain in WordPress, called wp2shell, which includes CVE-2026-63030 and CVE-2026-60137. Hackers gained access to 49 organizations across 29 countries, mainly involving government agencies and small businesses.
More recently, the hacker targeted Zyxel GS1900 Smart Managed Switches using a novel exploit of CVE-2026-7273, GreyNoise said. Sensitive exploitation was confirmed in 996 switches across 48 countries, according to the researchers.
The researchers warned that the adversary is also using 17 different scripts to bypass Microsoft’s Antimalware Scan Interface. The actor is escalating privileges through token impersonation and creating a local administrator account.
The suspected hacker shares overlaps with an adversary known as Red Heron. Earlier this month, researchers at Acronis tracked Red Heron exploiting CVE-2026-60004, a critical vulnerability in Gitea, a self-hosted source code management platform.