CYOPS · Cyber Operations

One operator, ten products, and a known-exploited list that arrives after the exfiltration

GreyNoise has published a three-month campaign it tracks as Kapibala, assessed as the same as or related to the Red Heron cluster documented by Acronis. The operator's tempo is set by public proof-of-concept availability, and the authoritative record of exploited flaws trails it by weeks.

A rolling n-day campaign, documented end to end

GreyNoise has published an account of a campaign it tracks as Kapibala, named after two accounts the operator created on compromised hosts [1]. The research team assesses the actor as a suspected Chinese speaker possibly working in UTC+8, based on the operational timeline and the volume of Chinese-language comments in custom tooling, and assesses the group as the same as or related to Red Heron, previously documented by Acronis [1]. That is the researchers’ assessment and is reported here as such.

The value of the publication is the table. Between 11 June and 3 September 2026 the operator is recorded exploiting PAN-OS GlobalProtect, Ubiquiti UniFi OS, FlowiseAI, WordPress, the Linux kernel, Gitea, Nuclio, Zyxel GS1900 switches, SENAITE LIMS and Proxmox VE [1]. Ten technologies in twelve weeks. Nothing in the set is a zero-day. Every entry is an n-day, taken up after a patch and a public exploit existed.

The cadence is the finding. Acronis’ Red Heron report, published 13 September and authored by Subhajeet Singha, timestamps the Gitea sequence precisely: Gitea 1.27.1 patched CVE-2026-60004 on 27 July; the public advisory and proof-of-concept followed on 28 July; the operator began weaponising on 29 July; 1,386 Gitea instances across seven countries were scanned on 30 July; a Taiwan-focused target list was compiled on 31 July; batch exploitation ran on 3 and 4 August [2][3]. Two days from public proof-of-concept to operational use.

The WordPress sequence is the same shape. The wp2shell chain — CVE-2026-63030, a REST API batch-route confusion flaw, chained with CVE-2026-60137, a SQL injection in WP_Query — was disclosed and patched on 17 July 2026 [4][5][6]. Patchstack reported in-the-wild activity within hours; VulnCheck’s sensor network detected exploitation by 20 July; more than 24 distinct public proof-of-concept exploits were verified by 19 July [6][8]. GreyNoise records this operator’s WordPress phase beginning 20 July [1]. Three days.

The known-exploited catalogue is a lagging record

Of the ten technologies in GreyNoise’s table, five carried no CISA known-exploited listing at the time of publication [1]. The Zyxel case is the clearest. Zyxel published its advisory for CVE-2026-7273 on 16 June 2026, describing a stack-based buffer overflow in a CGI program that could permit a LAN-based, unauthenticated attacker to execute operating system commands via a crafted HTTP request [7]. On 17 August the operator exploited and exfiltrated data from 996 GS1900 switches across 48 countries [1][9]. The flaw was added to the known-exploited catalogue on 21 September with a federal remediation deadline of 24 September [10][13]; one analysis dates the addition to 22 September [11]. The sources differ and both dates are given here.

Five weeks separated the mass compromise from the listing. The listing is not at fault — it records confirmed exploitation, and confirmation arrived when GreyNoise published. The operational conclusion is about how the list is used. A patch programme triggered by known-exploited entries will always act after the exploitation it is meant to prevent. The trigger that would have worked in every case here is the publication of a working proof-of-concept.

The Zyxel advisory carries a second lesson. It describes the attacker as LAN-based [7], which is accurate about the intended deployment and says nothing useful about the installed reality. Nearly a thousand switches in 48 countries were reachable and compromised, which means their management interfaces were not on a LAN in any meaningful sense. A vendor’s threat model describes the product as designed. An asset inventory describes it as deployed. Only the second one is defensible.

What was actually taken

GreyNoise records 49 WordPress victim organisations across 29 countries, predominantly small business and government [1]. The most severe single case is a Western governmental organisation compromised on 22 July 2026, from which the operator took more than 18,000 sensitive records including accounts, plaintext passwords and personally identifiable information associated with law enforcement and government agencies [1][9]. The organisation is not named by the source and is not named here.

Plaintext passwords is the detail that outlives the patch. A WordPress core update closes the route in; it does not invalidate a credential set already in someone’s possession, and credentials harvested from a small government site are reusable wherever their owners reused them. The wp2shell chain creates administrator accounts as part of its effect [4][12], so patching alone leaves the operator’s access in place.

Acronis’ figures for the Gitea phase show the same preference for reachability over prestige: 13 confirmed compromises across six countries — Taiwan four, the United States four, Canada two, Argentina, Qatar and Sri Lanka one each — spanning defence, elections, energy, aerospace, telecommunications, government, public safety and research [3]. The malware is named JITTERLY, a C++ Linux implant with more than thirty post-exploitation commands, and SIXZUT, a previously undocumented LD_PRELOAD rootkit [2][3]. Acronis assesses China-linked operations with moderate confidence, on the basis of Simplified Chinese labelling, the Taiwan target classification and alignment with collection priorities [3].

Two research teams, one question, opposite answers

GreyNoise suspects a language model was involved in producing the custom tooling, citing behaviour patterns in the code, rapid iteration, code comments, and superficial variations between iterations that would generally be a waste of time for a human [1]. Acronis’ Subhajeet Singha states that the actor adapted publicly available proof-of-concept code and other open-source tools rather than building custom exploitation frameworks with artificial intelligence [3].

These are assessments of overlapping activity by two teams looking at different artefacts, and they point in opposite directions. R3KONX publishes both and adopts neither. The disagreement is worth recording because the tooling question has begun to drive procurement conversations, and here two competent teams reading the same actor cluster reach different conclusions from the evidence each holds.

What is not in dispute is the infrastructure overlap on which the "same or related" assessment rests. GreyNoise lists a command-and-control domain family at *.981666.xyz among the Kapibala indicators [1]; Acronis records s2.981666.xyz on port 8082 for Red Heron [2].

What to do

  • Treat the appearance of a working public proof-of-concept as the patch trigger, not the known-exploited listing. On this campaign’s record the gap between the two ran from days to five weeks [1][9][10].
  • Take switch, access point and firewall management interfaces off the public internet and verify it from outside. The Zyxel advisory assumes LAN access; 996 devices in 48 countries say otherwise [1][7][13].
  • For WordPress estates, confirm core is at 6.8.6, 6.9.5 or 7.0.2 or later, then audit administrator accounts, plugin directories and uploads created since 17 July. The chain creates administrators, so patching without an audit leaves access intact [4][5][12].
  • Rotate any credential that was stored or transmitted in plaintext on an affected site, and check reuse of those credentials elsewhere [1].
  • Check self-hosted developer infrastructure — Gitea, CI runners, artefact stores. It holds source code and secrets, and it sits outside most asset registers [2][3].
  • Ingest the published indicators, including the command-and-control domain family and the backdoor file hashes, and search historically rather than only forward [1][2].

The regional exposure is concrete. Taiwan was the single largest victim group in the Acronis dataset [3], the WordPress victims span 29 countries and the switch compromises 48 [1]. Zyxel GS1900 switches are ordinary small-office and branch equipment across Malaysian and ASEAN estates, and self-hosted Gitea is common in regional universities and research groups. This operator did not select for importance. It selected for what was reachable, and government data turned up inside small estates because that is where small estates keep it.

Sources

Every R3KONX article cites its primary material. 13 sources, in order of first citation. Links open the original publication.

  1. Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation GreyNoise Intelligence · 2026-09-23
  2. Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit Acronis Threat Research Unit · 2026-09-13
  3. Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries The Hacker News · 2026-09-14
  4. CVE-2026-63030: wp2shell, a Critical Remote Code Execution Vulnerability in WordPress Core Rapid7 · 2026-07-17
  5. wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently Asked Questions About Remote Code Execution Tenable · 2026-07-17
  6. WP2Shell Vulnerabilities: CVE-2026-60137 and CVE-2026-63030 VulnCheck · 2026-07-17
  7. Zyxel security advisory for stack-based buffer overflow vulnerability in GS1900 series switches Zyxel Networks · 2026-06-16
  8. CVE-2026-63030 & CVE-2026-60137: WordPress Core Pre-Authentication RCE Overview & Takeaways NetSPI · 2026-07-20
  9. Chinese hackers exploit WordPress, Zyxel flaws to steal govt data BleepingComputer · 2026-09-24
  10. U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog Security Affairs · 2026-09-22
  11. Zyxel GS1900 CVE-2026-7273 Is Actively Exploited: Patch These 10 Switch Models AiCybr · 2026-09-23
  12. WordPress wp2shell (CVE-2026-63030): CISO FAQ & Fix SOCRadar · 2026-07-21
  13. CISA orders feds to patch actively exploited Zyxel flaw by Thursday BleepingComputer · 2026-09-22

Researched and written by the R3KONX analysis desk from the cited primary material, principally GreyNoise's Kapibala publication, Acronis TRU's Red Heron report, Zyxel's own advisory and the wp2shell vulnerability analyses from Rapid7, Tenable, VulnCheck, NetSPI and SOCRadar. Methodological caveats: cisa.gov could not be retrieved at the time of writing, so all KEV catalogue dates are taken from secondary sources that quote them and one such date is disputed between sources; both are published. Actor attribution is reported strictly as the assessment of the named research team, not as an R3KONX finding, and the compromised government organisation is not named because no source names it. Corrections: event@r3konx.asia.

R3KONX 2027

Work in this domain? So does the programme

4–6 May 2027, World Trade Centre Kuala Lumpur. Curated talks, hands-on training and The BattleGrid.