ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
ownCloud flaw exploited to steal nuclear records from Philippine research body. CISA added CVE-2023-49105 to KEV catalog. Hunt.io identified open directory with scripts targeting ownCloud instance.
Intelligence analysis by Qwen 2.5 (3B)

A Chinese-speaking threat actor used a critical ownCloud vulnerability to steal nuclear records from a Philippine research body. CISA added the vulnerability to its KEV catalog. Hunt.io identified an open directory with scripts targeting ownCloud instances.
A bad guy found a way to trick a computer system to let them see and change files they shouldn't. They used this to look at important nuclear information from a research place in the Philippines.
Analysis
{"
Vulnerability Details and Impact on ownCloud Instances":"CVE-2023-49105 is a WebDAV API authentication bypass vulnerability in ownCloud. It allows attackers to access, modify, or delete any file without authentication if the username of the victim is known and the victim has no signing-key configured. This vulnerability impacts core versions from 10.6.0 through 10.13.0 and was fixed in version 10.13.1. The threat actor used this vulnerability to target a nuclear research body in the Philippines.","
Hunt.io's Findings":"Hunt.io identified an open directory on the host '31.58.209[.]241' that staged custom Python scripts, open-source offensive security tooling, and exfiltrated data from two Philippine organizations. The scripts targeted an ownCloud instance operated by a nuclear research body, using pre-signed URLs generated with an empty signing secret, which allowed for the unauthenticated retrieval of files over WebDAV. The threat actor is estimated to have downloaded 176 files totaling about 372 MB from the nuclear research entity and stored them across five staging directories. This includes nuclear-material account records, draft strategic plans, research reactor core components, historical fuel inventories, and employee personal information.","
WordPress Exploitation":"A separate intrusion exploited a critical flaw in the LiteSpeed Cache plugin for WordPress (CVE-2024-28000) to obtain elevated access to the WordPress site operated by another Philippines company. A Python script ('brute_xmlrpc.py') identified in the open directory targets the same site with an XML-RPC brute-force attack to guess account credentials, thereby giving the attackers a pathway independent of CVE-2024-28000. Further analysis of the WordPress source code has unearthed an active, possibly unrelated compromise that leverages EtherHiding to extract HTML content from an Ethereum smart contract and ultimately serve a Google verification page that's common in ClickFix-style attacks."}
Key points
- ownCloud vulnerability CVE-2023-49105 was exploited to steal nuclear records from a Philippine research body.
- The threat actor used a pre-signed URL with an empty signing secret to access files without authentication.
- The threat actor also exploited a critical flaw in the LiteSpeed Cache plugin for WordPress.
- The threat actor used a Python script to guess account credentials on the WordPress site.
- The threat actor used EtherHiding to extract HTML content from an Ethereum smart contract and serve a Google verification page.
By patching the ownCloud vulnerability, organizations can prevent bad guys from using this trick to see sensitive information.
If the bad guy finds a new way to trick the system, they might still be able to see the information.



