INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Philippine Nuclear Agency Targets Hit by Suspected Chinese Operator
| 2026-09-02 01:36 CRITICAL HIGH STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A recent surge in reported cyber intrusion activity by suspected Chinese actors against Philippine government, defense, and critical infrastructure organizations has raised concerns over the country's vulnerability to espionage. Microsoft's Digital Defense Report 2025 placed the Philippines 20th globally among countries most impacted by cyber activity in the first half of 2025, highlighting a growing threat landscape. The report noted that Chinese state actors were targeting the Philippines as part of broader Southeast Asia espionage against IT, government, and academic sectors. A targeted attack on the Philippine Nuclear Agency and Naval Contractor using known vulnerabilities has been attributed to a suspected Chinese-speaking operator, with old, unpatched flaws giving attackers access to sensitive data.
Technical Mitigations AI-generated
• Implementing regular patch management for servers and applications to prevent exploitation of known vulnerabilities.
• Conducting thorough vulnerability assessments and penetration testing to identify potential entry points for attackers.
• Utilizing intrusion detection systems (IDS) or security information and event management (SIEM) solutions to monitor network traffic and detect suspicious activity.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
sn•••••.com
hu•••••.io
ti•••••.com
fi•••••.com
ro•••••.txt
hxxp://••••••••••••••••••••
7447d0••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
10df34••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Dark CaracalDark CaracalTransparent TribeTransparent Tribe
GrandoreiroGrandoreiro
CVE-2024-2800CVE-2024-2800
CVE-2024-28000CVE-2024-28000
CVE-2023-49105CVE-2023-49105
Target & Sectors
ASEAN
ASEAN
FIVE_EYES
FIVE_EYES
APAC
APAC
educationeducation
energyenergy
financefinance
governmentgovernment
Incident Timeline
the first half of 2025
Chinese state actors targeted the Philippines' IT, government, and academic sectors as part of broader Southeast Asia espionage.
Click on any entity below to view its context and source!
industry
Government
Microsoft's Digital Defense Report 2025 placed the Philippines 20th globally among countries most impacted by cyber activity in the first half of 2025, and noted Chinese state actors targeting the Philippines as part of broader Southeast Asia espionage against IT, government, and academic sectors
References:
hxxps://hunt[.]io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor?ut…
industry
Defense
Microsoft's Digital Defense Report 2025 placed the Philippines 20th globally among countries most impacted by cyber activity in the first half of 2025, and noted Chinese state actors targeting the Philippines as part of broader Southeast Asia espionage against IT, government, and academic sectors
References:
hxxps://hunt[.]io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor?ut…
source_region
China
Microsoft's Digital Defense Report 2025 placed the Philippines 20th globally among countries most impacted by cyber activity in the first half of 2025, and noted Chinese state actors targeting the Philippines as part of broader Southeast Asia espionage against IT, government, and academic sectors
References:
hxxps://hunt[.]io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor?ut…
target_region
Philippines
Microsoft's Digital Defense Report 2025 placed the Philippines 20th globally among countries most impacted by cyber activity in the first half of 2025, and noted Chinese state actors targeting the Philippines as part of broader Southeast Asia espionage against IT, government, and academic sectors
References:
hxxps://hunt[.]io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor?ut…
tactic
Espionage
Microsoft's Digital Defense Report 2025 placed the Philippines 20th globally among countries most impacted by cyber activity in the first half of 2025, and noted Chinese state actors targeting the Philippines as part of broader Southeast Asia espionage against IT, government, and academic sectors
References:
hxxps://hunt[.]io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor?ut…
target_region
APAC
Microsoft's Digital Defense Report 2025 placed the Philippines 20th globally among countries most impacted by cyber activity in the first half of 2025, and noted Chinese state actors targeting the Philippines as part of broader Southeast Asia espionage against IT, government, and academic sectors
References:
hxxps://hunt[.]io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor?ut…
observable
fine-work-team.com
Microsoft's Digital Defense Report 2025 placed the Philippines 20th globally among countries most impacted by cyber activity in the first half of 2025, and noted Chinese state actors targeting the Philippines as part of broader Southeast Asia espionage against IT, government, and academic sectors
References:
hxxps://hunt[.]io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor?ut…
observable
hunt.io
Microsoft's Digital Defense Report 2025 placed the Philippines 20th globally among countries most impacted by cyber activity in the first half of 2025, and noted Chinese state actors targeting the Philippines as part of broader Southeast Asia espionage against IT, government, and academic sectors
References:
hxxps://hunt[.]io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor?ut…
observable
snake.zooparkko.com
Microsoft's Digital Defense Report 2025 placed the Philippines 20th globally among countries most impacted by cyber activity in the first half of 2025, and noted Chinese state actors targeting the Philippines as part of broader Southeast Asia espionage against IT, government, and academic sectors
References:
hxxps://hunt[.]io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor?ut…
observable
timelevel12.com
Microsoft's Digital Defense Report 2025 placed the Philippines 20th globally among countries most impacted by cyber activity in the first half of 2025, and noted Chinese state actors targeting the Philippines as part of broader Southeast Asia espionage against IT, government, and academic sectors
References:
hxxps://hunt[.]io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor?ut…
organisation
Microsoft
Microsoft's Digital Defense Report 2025 placed the Philippines 20th globally among countries most impacted by cyber activity in the first half of 2025, and noted Chinese state actors targeting the Philippines as part of broader Southeast Asia espionage against IT, government, and academic sectors
References:
hxxps://hunt[.]io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor?ut…
organisation
Digital Defense Report
Microsoft's Digital Defense Report 2025 placed the Philippines 20th globally among countries most impacted by cyber activity in the first half of 2025, and noted Chinese state actors targeting the Philippines as part of broader Southeast Asia espionage against IT, government, and academic sectors
References:
hxxps://hunt[.]io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor?ut…
2026/09/02
A suspected Chinese-speaking operator exploited known vulnerabilities in internet-facing ownCloud and WordPress systems to target a Philippine nuclear research body and a marine engineering company that supports the Philippine Navy.
Click on any entity below to view its context and source!
threat_actor
Dark Caracal
Related:
Dark Caracal Adds New Malware to Cyber Espionage Arsenal
"Everything we saw is collection and exfiltration, no disruption tooling," he says.
organisation
IOC - Philippine Nuclear Agency
IOC - Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities.
threat_actor
Transparent Tribe
Related:
Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks
Yet, more than 24 months after their disclosures, the vulnerabilities remained exploitable on internet-facing systems belonging to highly sensitive organizations.
data_breach
9 gigabytes
Related:
'Grandoreiro' Malware Resurfaces With Mexico Campaign
While Hunt.io cannot confirm that "9 gigabytes left the building," the credentials, documents, and data all indicate a broader breach, Borges says.
"
Nuclear Agency Data Exfiltrated
While Hunt.io's researchers found nearly 1.2 gigabytes of data on the server in Amsterdam — and only 372 megabytes that appeared to be victim data — a spreadsheet "named after the parent ministry to the nuclear agen…
“A recovered CSV references roughly 9 GB of material stolen from the nuclear agency, most absent from the current directories contents, and a compromise of a project management application, indicating a possible third victim.”
Hunt.io disclosed th…
However, a CSV created by the attacker referred to roughly 9 GB of stolen data.
data_breach
1.2 GB
"
Nuclear Agency Data Exfiltrated
While Hunt.io's researchers found nearly 1.2 gigabytes of data on the server in Amsterdam — and only 372 megabytes that appeared to be victim data — a spreadsheet "named after the parent ministry to the nuclear agen…
Researchers from threat hunting platform Hunt.io discovered the files on an
ownCloud
server hosted in Amsterdam that appeared to be a hub for the attackers, hosting offensive tools and stolen data, including 1,310 files totaling nearly 1.2 GB.
infrastructure
10.13.1
The main entry point was likely the nuclear research body’s internet-facing ownCloud service, compromised by exploiting
CVE-2023-49105
, an authentication-bypass flaw in ownCloud versions before 10.13.1.
data_breach
1,310 files
Researchers from threat hunting platform Hunt.io discovered the files on an
ownCloud
server hosted in Amsterdam that appeared to be a hub for the attackers, hosting offensive tools and stolen data, including 1,310 files totaling nearly 1.2 GB.
The directory contained 1,310 files in 86 folders, totaling 1.17 GB, including scripts, stolen data and tools such as Sliver, Metasploit and Mettle.
data_breach
1.17 GB
The directory contained 1,310 files in 86 folders, totaling 1.17 GB, including scripts, stolen data and tools such as Sliver, Metasploit and Mettle.
data_breach
372 megabytes
…gency Data Exfiltrated
While Hunt.io's researchers found nearly 1.2 gigabytes of data on the server in Amsterdam — and only 372 megabytes that appeared to be victim data — a spreadsheet "named after the parent ministry to the nuclear agency" docume…
The exposed server held 176 files, about 372 MB in total.
data_breach
176 files
The exposed server held 176 files, about 372 MB in total.
infrastructure
10.13.3
Organisations using ownCloud should upgrade to version 10.13.3 or later, apply the vendor’s relevant fixes and ensure that pre-signed URLs use a strong, non-empty signing key.
infrastructure
6.4
For WordPress, organisations should update LiteSpeed Cache to version 6.4 or later, remove or restrict XML-RPC when it is not needed, enforce strong unique administrator passwords and require multi-factor authentication.
data_breach
192 MB SQL
Researchers additionally recovered a 192 MB SQL dump from a ZKTeco BioTime attendance and personnel system.
infrastructure
174 unique IP addresses
Hunt.io found 174 unique IP addresses hosting pages with the same NoChain loader strings and smart-contract reference, but said the evidence did not link that activity to the operator who attacked the nuclear and naval-linked targets.
Tactical Metrics
Metrics
data_breach
9
Gigabytes
Click for context!
Related:
'Grandoreiro' Malware Resurfaces With Mexico Campaign
While Hunt.io cannot confirm that "9 gigabytes left the building," the credentials, documents, and data all indicate a broader breach, Borges says.
"
Nuclear Agency Data Exfiltrated
While Hunt.io's researchers found nearly 1.2 gigabytes of data on the server in Amsterdam — and only 372 megabytes that appeared to be victim data — a spreadsheet "named after the parent ministry to the nuclear agen…
“A recovered CSV references roughly 9 GB of material stolen from the nuclear agency, most absent from the current directories contents, and a compromise of a project management application, indicating a possible third victim.”
Hunt.io disclosed th…
However, a CSV created by the attacker referred to roughly 9 GB of stolen data.
Metrics
data_breach
1,310
Files
Researchers from threat hunting platform Hunt.io discovered the files on an
ownCloud
server hosted in Amsterdam that appeared to be a hub for the attackers, hosting offensive tools and stolen data, including 1,310 files totaling nearly 1.2 GB.
The directory contained 1,310 files in 86 folders, totaling 1.17 GB, including scripts, stolen data and tools such as Sliver, Metasploit and Mettle.
Metrics
data_breach
1
Gb
Researchers from threat hunting platform Hunt.io discovered the files on an
ownCloud
server hosted in Amsterdam that appeared to be a hub for the attackers, hosting offensive tools and stolen data, including 1,310 files totaling nearly 1.2 GB.
"
Nuclear Agency Data Exfiltrated
While Hunt.io's researchers found nearly 1.2 gigabytes of data on the server in Amsterdam — and only 372 megabytes that appeared to be victim data — a spreadsheet "named after the parent ministry to the nuclear agen…
Metrics
data_breach
372
Megabytes
…gency Data Exfiltrated
While Hunt.io's researchers found nearly 1.2 gigabytes of data on the server in Amsterdam — and only 372 megabytes that appeared to be victim data — a spreadsheet "named after the parent ministry to the nuclear agency" docume…
The exposed server held 176 files, about 372 MB in total.
Metrics
data_breach
1
Gb
The directory contained 1,310 files in 86 folders, totaling 1.17 GB, including scripts, stolen data and tools such as Sliver, Metasploit and Mettle.
Metrics
infrastructure
10.13.1
Software Version
The main entry point was likely the nuclear research body’s internet-facing ownCloud service, compromised by exploiting
CVE-2023-49105
, an authentication-bypass flaw in ownCloud versions before 10.13.1.
Metrics
infrastructure
10.13.3
Software Version
Organisations using ownCloud should upgrade to version 10.13.3 or later, apply the vendor’s relevant fixes and ensure that pre-signed URLs use a strong, non-empty signing key.
Metrics
infrastructure
6.4
Software Version
For WordPress, organisations should update LiteSpeed Cache to version 6.4 or later, remove or restrict XML-RPC when it is not needed, enforce strong unique administrator passwords and require multi-factor authentication.
Metrics
data_breach
192
Mb Sql
Researchers additionally recovered a 192 MB SQL dump from a ZKTeco BioTime attendance and personnel system.
Metrics
infrastructure
174
Unique Ip Addresses
Hunt.io found 174 unique IP addresses hosting pages with the same NoChain loader strings and smart-contract reference, but said the evidence did not link that activity to the operator who attacked the nuclear and naval-linked targets.
Metrics
data_breach
176
Files
The exposed server held 176 files, about 372 MB in total.
Intelligence Sources
Security Affairs
2026-08-29
Dark Reading
2026-09-02
AlienVault OTX
2026-09-02
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T06:10
Comprehensive Tactical Telemetry
Highly Correlated Entities
32x
organisation
Identified Entity
Microsoft
entity
12x
timeline
Temporal Reference
2025
date
8x
target region
Target Country
China
country
4x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
3x
industry
Targeted Sector
Government
sector
3x
source region
Origin Country
China
country
3x
vulnerability
Exploited CVE
CVE-2023-49105
cve
3x
infrastructure
Software Version
10.13.1
version
2x
tactic
Cyber Operation Type
Espionage
tactic
2x
threat actor
APT Group
Transparent Tribe
actor
2x
general metric
%
51
%
2x
data breach
Files
1,310
files
2x
data breach
Gb
1
gb
2x
malware
Offensive Tool
Sliver
tool
2x
attribution
Attributing Entity
CSV
authority
Contextual Telemetry
Context Block
10 METRICS
target region
Target Region
APAC
region
campaign
Campaign
Campaign
While Hunt
operation
malware
Malware Payload
Grandoreiro
tool
data breach
Gigabytes
9
gigabytes
data breach
Megabytes
372
megabytes
general metric
Folders
86
folders
general metric
Cache
6
cache
general metric
Port
8,000
port
data breach
Mb Sql
192
mb sql
infrastructure
Unique Ip Addresses
174
unique ip addresses
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.