OffPerimeter · Threat advisories
Campaign advisory
highPublished 2026-09-23 · 0 indicators

Red Heron group exploits wp2shell and ZyXEL flaws to steal govt data

A Chinese-speaking threat actor linked to the Red Heron group has been exploiting vulnerabilities in WordPress, ZyXEL GS1900 switches, and other technologies to steal sensitive data from government and high-value targets. The campaign has compromised over 996 devices and more than 18,500 records, including PII and credentials from government and law-enforcement agencies. The threat actor is suspected of using a combination of remote code execution and lateral movement techniques to achieve their objectives.

ShareXLinkedInWhatsApp
First seen
2026-06-01
Last seen
2026-09-22
Threat actors
Red Heron group
Malware
wp2shell
Sectors
Government, Technology, Critical Infrastructure
Countries
United States, Russia, Ukraine, China

How it works

The campaign begins with initial access through the exploitation of known vulnerabilities in WordPress (wp2shell) and ZyXEL GS1900 switches. Once access is gained, the threat actor deploys backdoors and establishes persistence. They then move laterally within the network to access sensitive data, which is exfiltrated to command-and-control servers controlled by the Red Heron group.

Techniques (MITRE ATT&CK)

What to do

References

ShareXLinkedInWhatsApp