GreyNoise is confident activity from this date onward is associated with a single malicious cyber actor.
34 days with no dated recordMay 8–Jun 10
Jun 11
PAN-OS GlobalProtect targeted
Vulnerability unknown. CISA KEV: N/A.
Jun 12
Exploitation attempts
UniFi OS exploitation attempted
A chain of CVE-2026-34908, CVE-2026-34909 and CVE-2026-34910, in an attempt to make devices download and run a backdoor from a staging server. Added to CISA KEV Jun 23.
Jun 15
Exploitation attempts
Second UniFi OS attempt
A different download URL, on what appears to be third-party infrastructure associated with a Taiwanese manufacturing company.
27 days with no dated recordJun 16–Jul 12
Jul 13
Exploitation attempts
FlowiseAI exploitation
CVE-2026-56271. Not in CISA KEV at publication.
6 days with no dated recordJul 14–Jul 19
Jul 20
Exploitation attempts
WordPress exploitation begins
On or about Jul 20: the wp2shell chain (CVE-2026-63030, CVE-2026-60137). Success against at least 49 organizations across 29 countries. Added to CISA KEV Jul 21.
Jul 22
Exploitation attempts
01:27:00 UTC
Western government WordPress site exploited
A custom exploit chain for CVE-2026-63030 and CVE-2026-60137, then a custom webshell deployed.
Jul 22
01:38:29 UTC
WordPress user table dumped
13 WordPress administrator accounts taken.
Jul 22
01:48:38–02:05:11 UTC
Masquerading account added
Logged into wp-admin and added an account posing as a valid address at the target's domain, its registration date set to a day in 2025 to blend in.
Jul 22
02:09:58 UTC
Collection plugin uploaded
A custom information collection plugin to enumerate the WordPress install end to end.
Jul 22
02:22:36 UTC
Webshell reconnaissance begins
The previously uploaded webshell is used for reconnaissance and the rest of the intrusion.
Jul 22
02:31:12–03:07:38 UTC
AMSI bypass and privilege escalation tried
At least 17 script variations in an attempt to bypass AMSI, escalate privileges by token impersonation and theft, create a local administrator account and dump registry data.
Jul 22
03:17:41 UTC
Cleartext credentials found
A custom tool searched readable files and found credentials to a backend SQL database.
Jul 22
03:30:41 UTC
Files packed into a ZIP archive
Staged with PowerShell in a web-reachable path.
Jul 22
03:31:25 UTC
ZIP archive downloaded
Contains source code, credentials and additional sensitive information.
Jul 22
04:02:01 UTC
Password spray reaches the SQL database
The credentials found were sprayed with custom tools; access gained to an internal SQL database.
Jul 22
04:08:32 UTC
Bulk extraction tools run
Two tools written and run to bulk extract data from the SQL server, using archiving and staging similar to before.
Jul 22
04:09:20 UTC
At least 18,566 records taken
Downloaded from the SQL database, including accounts, plaintext passwords and PII tied to law enforcement and government agencies.
Jul 22
05:36:41 UTC
Activity resumes
Attempts broader internal password spraying; operations continue until at least 06:01:40 UTC.
Jul 23
Exploitation attempts
Linux kernel exploitation
CVE-2022-0847. In CISA KEV since Apr 25, 2022.
6 days with no dated recordJul 24–Jul 29
Jul 30
Exploitation attempts
Gitea exploitation
CVE-2026-60004. Added to CISA KEV Aug 25.
13 days with no dated recordJul 31–Aug 12
Aug 13
Exploitation attempts
Nuclio exploitation
CVE-2026-79756. Not in CISA KEV at publication.
Aug 17
Exploitation attempts
ZyXEL GS1900 switches exploited
On or about Aug 17: a novel CVE-2026-7273 exploit took data from 996 switches in 48 countries, including configurations and hashed root credentials. Not in CISA KEV at publication.
9 days with no dated recordAug 18–Aug 26
Aug 27
Exploitation attempts
SENAITE LIMS exploitation
CVE-2026-54569. Not in CISA KEV at publication.
6 days with no dated recordAug 28–Sep 2
Sep 3
Exploitation attempts
Proxmox VE exploitation
CVE-2023-54391. Not in CISA KEV at publication.
Source: GreyNoise Global Observation Grid and adversary infrastructure.
Times are UTC. Jul 22 times come from preserved file timestamps and may differ from a forensic investigation.