INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Philippine Nuclear Agency Targets Hit by Suspected Chinese Operator

| 2026-09-02 01:36 CRITICAL HIGH STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A recent surge in reported cyber intrusion activity by suspected Chinese actors against Philippine government, defense, and critical infrastructure organizations has raised concerns over the country's vulnerability to espionage. Microsoft's Digital Defense Report 2025 placed the Philippines 20th globally among countries most impacted by cyber activity in the first half of 2025, highlighting a growing threat landscape. The report noted that Chinese state actors were targeting the Philippines as part of broader Southeast Asia espionage against IT, government, and academic sectors. A targeted attack on the Philippine Nuclear Agency and Naval Contractor using known vulnerabilities has been attributed to a suspected Chinese-speaking operator, with old, unpatched flaws giving attackers access to sensitive data.
Technical Mitigations AI-generated
• Implementing regular patch management for servers and applications to prevent exploitation of known vulnerabilities. • Conducting thorough vulnerability assessments and penetration testing to identify potential entry points for attackers. • Utilizing intrusion detection systems (IDS) or security information and event management (SIEM) solutions to monitor network traffic and detect suspicious activity.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

sn•••••.com
hu•••••.io
ti•••••.com
fi•••••.com
ro•••••.txt
hxxp://••••••••••••••••••••
7447d0••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
10df34••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Dark CaracalDark CaracalTransparent TribeTransparent Tribe GrandoreiroGrandoreiro CVE-2024-2800CVE-2024-2800 CVE-2024-28000CVE-2024-28000 CVE-2023-49105CVE-2023-49105
Target & Sectors
ASEAN ASEAN FIVE_EYES FIVE_EYES APAC APAC educationeducation energyenergy financefinance governmentgovernment
Incident Timeline
‎the first half of 2025
Chinese state actors targeted the Philippines' IT, government, and academic sectors as part of broader Southeast Asia espionage.
industry Government
industry Defense
source_region China
target_region Philippines
tactic Espionage
target_region APAC
observable fine-work-team.com
observable hunt.io
observable snake.zooparkko.com
observable timelevel12.com
organisation Microsoft
organisation Digital Defense Report
‎2026/09/02
A suspected Chinese-speaking operator exploited known vulnerabilities in internet-facing ownCloud and WordPress systems to target a Philippine nuclear research body and a marine engineering company that supports the Philippine Navy.
threat_actor Dark Caracal
organisation IOC - Philippine Nuclear Agency
threat_actor Transparent Tribe
data_breach 9 gigabytes
data_breach 1.2 GB
infrastructure 10.13.1
data_breach 1,310 files
data_breach 1.17 GB
data_breach 372 megabytes
data_breach 176 files
infrastructure 10.13.3
infrastructure 6.4
data_breach 192 MB SQL
infrastructure 174 unique IP addresses
Tactical Metrics
Metrics
data_breach
9
Gigabytes
Metrics
data_breach
1,310
Files
Metrics
data_breach
1
Gb
Metrics
data_breach
372
Megabytes
Metrics
data_breach
1
Gb
Metrics
infrastructure
‎10.13.1
Software Version
Metrics
infrastructure
‎10.13.3
Software Version
Metrics
infrastructure
‎6.4
Software Version
Metrics
data_breach
192
Mb Sql
Metrics
infrastructure
174
Unique Ip Addresses
Metrics
data_breach
176
Files