Red Heron-linked wp2shell campaign targeting high-value entities
Campaign
Summary
Hide ▲
Show ▼
A Chinese-speaking threat actor tied to Red Heron is running a wp2shell campaign that has breached at least 49 organizations in 29 countries, expanding the risk of credential theft and government data exposure. The operation began in early June 2026 and used the same IP address for scans and attacks. It targeted high-value entities and combined exploitation with post-access recon and credential abuse. The campaign matters because it shows a coordinated, cross-border intrusion effort rather than isolated scanning.
Related Happenings
ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites
Campaign
H score32
First: 19.08.2026 18:00
Last: 19.08.2026 18:00
Sources 1
About this happening:
An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware...
ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites
CampaignAbout this happening: An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware...
Webworm multi-country targeting campaign against government and enterprise victims
Campaign
H score38
First: 20.05.2026 15:51
Last: 20.05.2026 15:51
Sources 1
About this happening:
Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...
Webworm multi-country targeting campaign against government and enterprise victims
CampaignAbout this happening: Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...
Timeline
-
22.09.2026 23:35 1 articles · 0h ago
Red Heron-linked wp2shell campaign targeting high-value entities
Initial DisclosureIn early June 2026, the actor’s same-IP scans and attacks began against high-value entities, establishing a cross-border campaign that would later expand to additional targets and technologies.
Show sources
- Chinese hackers exploit multiple technologies to steal govt data — www.bleepingcomputer.com — 22.09.2026 23:35
-
22.09.2026 23:35 1 articles · 0h ago
ZyXEL GS1900 switches exploited on August 17
Exploitation ObservedOn August 17, a Chinese-speaking threat actor exploited CVE-2026-7273 in ZyXEL GS1900 Smart Managed Switches, compromising 996 devices in 48 countries and extracting device configurations, network information, and hashed root-level credentials.
Show sources
- Chinese hackers exploit multiple technologies to steal govt data — www.bleepingcomputer.com — 22.09.2026 23:35