Red Heron group exploits wp2shell and ZyXEL flaws to steal govt data
A Chinese-speaking threat actor linked to the Red Heron group has been exploiting vulnerabilities in WordPress, ZyXEL GS1900 switches, and other technologies to steal sensitive data from government and high-value targets. The campaign has compromised over 996 devices and more than 18,500 records, including PII and credentials from government and law-enforcement agencies. The threat actor is suspected of using a combination of remote code execution and lateral movement techniques to achieve their objectives.
- First seen
- 2026-06-01
- Last seen
- 2026-09-22
- Threat actors
- Red Heron group
- Malware
- wp2shell
- Sectors
- Government, Technology, Critical Infrastructure
- Countries
- United States, Russia, Ukraine, China
How it works
The campaign begins with initial access through the exploitation of known vulnerabilities in WordPress (wp2shell) and ZyXEL GS1900 switches. Once access is gained, the threat actor deploys backdoors and establishes persistence. They then move laterally within the network to access sensitive data, which is exfiltrated to command-and-control servers controlled by the Red Heron group.
Techniques (MITRE ATT&CK)
- T1059 · ExecutionCommand and Scripting InterpreterThe threat actor uses command-line interfaces to execute malicious payloads and manage compromised systems.
- T1134 · PersistenceAccount ManipulationThe threat actor modifies user account settings to maintain long-term access to compromised systems.
What to do
- Apply the latest security patches for WordPress and ZyXEL GS1900 switches to mitigate known vulnerabilities.
- Monitor network traffic for unusual outbound connections to command-and-control servers.
- Implement strict access controls and multi-factor authentication for administrative accounts.
- Conduct regular vulnerability assessments and penetration testing to identify and remediate weaknesses.
- Deploy endpoint detection and response (EDR) tools to detect and respond to suspicious activities.
- Ensure that all systems are configured with the principle of least privilege to limit the impact of potential breaches.