Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Hacker

    Date: 08/27/2026

    Severity: High 

    Summary

    Suspected Chinese cyber actors have increasingly targeted Philippine government, defense, and critical infrastructure amid South China Sea tensions. Digital Defense Report 2025 ranked the Philippines 20th globally among countries most affected by cyber activity in H1 2025. On August 13, 2026, Attack Capture identified an exposed directory on the host 31.58.209[.]241 containing attacker tools, Python scripts, transfer logs, and stolen data. The scripts targeted an ownCloud server operated by a Philippine nuclear research organization, exploiting improperly configured pre-signed URLs. The flaw allowed attackers to bypass authentication and retrieve files through WebDAV using URLs generated with an empty signing secret. A separate intrusion targeted a WordPress website belonging to a Philippine marine engineering and shipbuilding company serving the Philippine Navy.

    Indicators of Compromise (IOC) List

    Domains/URLs

    fine-work-team.com/6272

    timelevel12.com/big

    snake.zooparkko.com/collect

    IP Address

    31.58.209.241

    Hash 

    7447d0d0c34779d4c519823b39bf6ddc16d2b34a226b82ee69da6f5b4a77ad82

    10df3451915ea35bcb17efe121415f24182680e2d07fc09df07ee695072104c1

    Smart contract address 

    0x58460d0b3d4d6b03761c89120393c0c676676496

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "fine-work-team.com/6272" or url like "fine-work-team.com/6272" and siteurl like "fine-work-team.com/6272" or domainname like "timelevel12.com/big" or url like "timelevel12.com/big" or siteurl like "timelevel12.com/big" or domainname like "snake.zooparkko.com/collect" or url like "snake.zooparkko.com/collect" or siteurl like "snake.zooparkko.com/collect"

    Detection Query 2 :

    dstipaddress IN ("31.58.209.241") or srcipaddress IN ("31.58.209.241")

    Detection Query 3 :

    sha256hash In ("7447d0d0c34779d4c519823b39bf6ddc16d2b34a226b82ee69da6f5b4a77ad82","10df3451915ea35bcb17efe121415f24182680e2d07fc09df07ee695072104c1")

    Reference:    

    https://hunt.io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor                                    


    Tags

    MalwareThreat ActorPhilippinesNuclear ReactorsGovernment Services and FacilitiesDefense Industrial BaseCritical InfrastructureExploitWebDAVWordPress

    « Previous Article

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags