Inside the Kapibala Cyber Attacks: WordPress Exploitation and Zyxel CVE-2026-7273 Under Active Exploitation

Octopus-like creature exploiting Zyxel server, WordPress compromised.

A sophisticated cyber espionage campaign orchestrated by a threat actor tracked as Kapibala has compromised critical infrastructure and government databases globally. Operating since mid-2026, this Chinese-speaking threat group has demonstrated high agility, utilizing automated vulnerability exploitation chains and custom-built malware to breach organizations. The campaign primarily leverages two distinct intrusion vectors: a WordPress exploit chain and the active exploitation of a critical Zyxel vulnerability.

The WordPress Exploitation Chain and Government Data Theft

The Kapibala threat actor initiated a series of automated attacks targeting public-facing WordPress installations. These attacks utilized a custom exploit chain known as “wp2shell,” which combines two vulnerabilities: CVE-2026-63030 and CVE-2026-60137. By successfully executing this chain, the attackers deployed a custom web shell referred to as the “kapibala plugin.”

Once inside, the threat actors engaged in the following malicious activities:

  • Credential Dumping: The attackers dumped WordPress user tables, compromising administrative accounts to secure initial persistence.
  • Evasion and Persistence: To evade security detection, they created rogue administrator accounts with backdated registration timestamps and installed custom assessment plugins.
  • Privilege Escalation: Using stolen administrative credentials, the threat actors performed password spraying against internal SQL databases.

This attack vector led to a significant breach at a Western government organization. The threat actors successfully exfiltrated at least 18,566 records containing highly sensitive data, including account credentials, plaintext passwords, and personally identifiable information (PII) associated with government and law enforcement personnel.

Exploiting Zyxel Switches: CVE-2026-7273

Parallel to the WordPress campaign, the Kapibala group launched a global campaign targeting Zyxel GS1900 Smart Managed Switches. This campaign exploited CVE-2026-7273, a critical stack-based buffer overflow vulnerability in the Common Gateway Interface (CGI) program of the switches. Boasting a CVSS score of 8.8, this flaw allows unauthenticated, adjacent attackers to execute operating system commands via crafted HTTP requests.

The threat actor utilized heavily obfuscated Python scripts to scan and exploit unpatched Zyxel devices globally. The campaign successfully compromised 996 switches across 48 countries, exfiltrating hashed root credentials, system configuration details, and network topology information. Alarmingly, a substantial portion of these compromised devices still relied on factory default credentials, significantly lowering the barrier to entry for the attackers.

CISA Intervention and Broader Campaign Scope

Due to the active exploitation of Zyxel devices, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-7273 to its Known Exploited Vulnerabilities (KEV) catalog, ordering federal agencies to apply vendor patches immediately. Beyond WordPress and Zyxel, the Kapibala group has scanned and targeted other widely used technologies, including Ubiquiti UniFi OS, FlowiseAI, Gitea, Nuclio, SENAITE LIMS, and Proxmox VE, as well as utilizing the Linux kernel DirtyPipe vulnerability.

Organizations must prioritize patching internet-facing assets immediately. Relying on default credentials and unpatched legacy systems provides threat actors like Kapibala with effortless pathways to sensitive backend networks.

Recommended Mitigation Strategies

To defend against the tactics observed in this campaign, security teams should implement the following measures:

  • Apply Security Patches: Immediately update Zyxel GS1900 switches to the latest firmware versions to patch CVE-2026-7273.
  • Secure WordPress Environments: Update all WordPress plugins and core installations to mitigate CVE-2026-63030 and CVE-2026-60137. Audit administrator accounts for unauthorized additions or backdated creation times.
  • Enforce Strong Credential Hygiene: Disable default credentials on all network hardware and enforce multi-factor authentication (MFA) across all administrative portals.
  • Monitor for Web Shells: Deploy endpoint detection and response (EDR) solutions to monitor for unusual file creation in web directories, specifically looking for unrecognized plugins or modified configuration files.

Leave a Reply

Your email address will not be published. Required fields are marked *

Close filters
Products Search