← Back to Daily Briefing

A sophisticated espionage campaign, attributed to Chinese-speaking threat actors, successfully compromised the Philippine Nuclear Research Agency by exploiting CVE-2023-49105. This critical authentication bypass vulnerability in ownCloud, stemming from an empty signing secret, enabled unauthorized access to sensitive document repositories. Post-exploitation, the adversary employed Microsoft Teams-based vishing, deployed the GoGRPC backdoor, and utilized the Sliver C2 framework to maintain persistence. The breach resulted in the exfiltration of critical nuclear research and naval defense documentation, highlighting the extreme risks of misconfigured authentication secrets in centralized document management systems.

  • Incident/Breach Overview

    • Targeted the Philippine Nuclear Research Agency to exfiltrate strategic state intelligence.
    • Successfully compromised institutional document repositories containing sensitive research.
    • Attributed to sophisticated, Chinese-speaking threat actors conducting targeted espionage.
  • Attack Vector & Vulnerability Mechanics

    • Exploited CVE-2023-49105, a critical authentication bypass vulnerability within the ownCloud platform.
    • The vulnerability is facilitated by an empty signing secret, allowing attackers to forge valid authentication tokens.
    • Leveraged the bypass to gain unauthorized access to restricted document repositories.
  • Post-Exploitation & Persistence Tactics

    • Utilized Microsoft Teams-based vishing and social engineering to facilitate lateral movement.
    • Deployed the GoGRPC backdoor to establish a stable, long-term presence within the network.
    • Employed the Sliver C2 framework for command-and-control operations and automated data theft.
  • Impact & Strategic Implications

    • Exfiltration of highly sensitive nuclear research records and maritime defense documentation.
    • Significant compromise of Philippine national security interests regarding nuclear and naval capabilities.
    • Demonstration of high-tier capability in combining software exploits with advanced social engineering.
  • Defensive Actions & Mitigation

    • Immediate patching of all ownCloud instances to remediate the CVE-2023-49105 vulnerability.
    • Audit and rotation of all signing secrets and authentication configurations within document management systems.
    • Implementation of behavioral monitoring to detect Sliver C2 traffic and GoGRPC network signatures.

Related posts

  1. gbhackers.com — Hackers Exploit CVE-2023-49105 to Steal Nuclear Records From Philippine Research Agency
  2. Fediwall
  3. Allsec
  4. Reddit
  5. Cyberpress
  6. Hunt
  7. Securityarsenal

LINK COPIED TO CLIPBOARD