Kapibala Attacker Plunders Government Databases
A solitary IP address, meticulously monitored by GreyNoise since early June, ultimately served as the primary entry point for a massive, multi-pronged cyberespionage campaign. This sophisticated operation simultaneously targeted diverse system classes, including WordPress installations, Zyxel switches, Ubiquiti platforms, Gitea servers, and numerous other vital services. Over several months, this singular operator successfully compromised dozens of organizations, ultimately penetrating sensitive government databases containing plaintext passwords and highly classified personal data.
The Devastating WordPress wp2shell Exploit
The most catastrophic episode unfolded on July 22. The attacker masterfully deployed the wp2shell exploit chain, leveraging CVE-2026-63030 and CVE-2026-60137. This terrifying combination permits unauthenticated remote code execution directly on vulnerable WordPress instances. Crucially, both underlying errors reside deep within the core CMS architecture itself, completely independent of vulnerable third-party plugins.
Upon breaching the digital perimeter of a prominent Western government organization, the malicious actor rapidly established persistence by installing a stealthy web shell. Subsequently, they extracted the entire WordPress user table, compromising 13 administrative accounts, and silently forged a rogue administrator profile dubbed “kapibala2”. The attacker ingeniously falsified the creation date of this illicit account, ensuring it masqueraded seamlessly as a legacy profile. Following this, the intruder scavenged plaintext passwords from exposed configuration files, dramatically escalated their privileges, and initiated lateral movement throughout the internal network infrastructure.
During a frantic five-hour window, the operator successfully infiltrated the internal SQL database, exfiltrating a staggering 18,566 highly sensitive records. The plundered data encompassed administrative accounts, plaintext passwords, and highly classified personal information intrinsically linked to various government structures and prominent law enforcement agencies. In totality, these vicious WordPress assaults compromised a minimum of 49 discrete organizations across 29 nations.
A Multi-Platform Assault Strategy
Simultaneously, this relentless operator orchestrated coordinated attacks against UniFi OS, Gitea, Flowise, Nuclio, SENAITE.CORE, Proxmox VE, and numerous other systems. A distinct, highly aggressive campaign specifically targeted Zyxel GS1900 series switches. The adversary ruthlessly exploited CVE-2026-7273, a critical stack overflow vulnerability buried within a specific CGI component. This flaw empowers any unauthenticated attacker residing on the local network to execute arbitrary system commands. GreyNoise documented 996 definitively compromised devices scattered across 48 countries. Shockingly, 564 of these compromised switches still possessed standard, factory-default credentials.
The true scale of this campaign vastly transcended merely three targeted products. GreyNoise definitively traced the deployment of at least 12 distinct vulnerabilities spanning nine disparate technologies. The attacker’s target acquisition list indiscriminately mixed recently disclosed zero-day flaws with ancient vulnerabilities for which patches have existed for years. This aggressive tactic perfectly aligns with the established behavioral model observed by GreyNoise, wherein sophisticated adversaries rapidly synthesize vulnerability disclosures into massive, automated scanning operations and immediate, real-world exploitation campaigns. For a comprehensive technical analysis, you can read more about how it is open season on the Kapibala attacker on the GreyNoise blog.
Attribution and the Role of AI in Exploit Development
Forensic artifacts embedded within the malware toolset and the operator’s distinct behavioral cadence strongly indicate a Chinese-speaking threat actor. GreyNoise tracks this adversary as “Kapibala” and currently suspects they are either intimately affiliated with, or identically match, the previously documented “Red Heron” APT group. Intriguingly, analysts suspect the attacker leveraged Large Language Models (LLMs) to construct several proprietary exploit tools. Specialists identified a bizarre series of nearly identical AMSI bypass variants, where only superficial naming conventions and trivial code structures were demonstrably altered.
The WordPress compromise is particularly illuminating because the wp2shell exploit devastated the core CMS architecture, rendering even pristine websites devoid of third-party extensions entirely vulnerable. Immediately following the publication of the initial technical vulnerability reports, massive, automated intrusion attempts commenced almost instantaneously. Security researchers documented these terrifying attacks a mere handful of days following the desperate release of emergency security updates.
A chillingly similar situation unfolded regarding Gitea servers. A critical vulnerability within the diffpatch mechanism permitted adversaries to execute arbitrary commands directly on the host server. Furthermore, the prevalence of unrestricted user registration drastically lowered the barrier for successful exploitation. By late August, thousands of vulnerable instances remained exposed across the internet, with attackers actively weaponizing Gitea servers to covertly deploy illicit cryptocurrency miners.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.