CyberSecurity.PH #046

Cyber espionage operations targeting Philippines and Myanmar government data; Compromised WiFi routers with pre-programed backdoors; Developments in AI generated disinformation campaigns; Analysis on recent cyberattacks targeting healthcare companies.

CTA Image

CyberSecurity.PH is now supported by the PSA Intelligence Cyber Risks

Learn more

APAC and Philippines

Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator

On August 27, 2026, threat intelligence researchers disclosed that a Chinese-speaking threat actor targeted the Philippine Nuclear Research Institute (PNRI) and a Naval contractor. The threat actor exploited a critical ownCloud flaw, identified as Common Vulnerabilities and Exposures (CVE)-2023-49105, and a WordPress exploit, CVE-2024-28000 (LiteSpeed Cache), to steal sensitive nuclear material records, research reactor data, personnel files, and encryption key material from the agency. 

Threat intelligence researchers noted that the attackers discovered an open directory containing tools for intrusion activity targeting the two Philippine institutions. The recovered CSV references contained approximately six gigabytes of stolen material from PNRI, including a compromised project management application. The stolen material also included 372 megabytes of reactor core components, fuel inventories, and radiation safety documents. The unidentified naval contractor’s stolen material also included documents referencing its affiliation with various Philippine-based science and research organizations. PSA Intelligence notes that Philippine authorities have yet to publicly acknowledge the information regarding the leak.

Redacted Information Showing Retrieved Files from the Nuclear Institute's ownCloud Instance. Photo by hunt.io, 2026

PSA Intelligence highlights that China-based threat actors are pointed to as the likely instigators of the leaks. Numerous docstrings, log markers, and folder names were written in Simplified Chinese, which are indicators that the threat actor is Chinese-speaking and is likely based in the People’s Republic of China (PRC). 

The Philippines has been a target of Chinese espionage activities in the past. The Philippine government had previously acknowledged Chinese-speaking advanced persistent threats (APTs) in targeting high-profile government institutions such as the Malacañang Palace in 2025, and the Philippine Coast Guard in 2024. One of the attacks was attributed to the Chinese APT group, APT41, which is a Chinese-state-sponsored espionage network specializing in financially motivated operations.

PSA Intelligence believes that the threat actor’s goal in the PNRI leak was to understand the PNRI’s organizational structure,  the country’s capabilities and expertise in the civilian use of nuclear technology,  and exploit existing cyber security vulnerabilities  for succeeding intelligence operations targeting Philippine institutions. 

PSA Intelligence highlights the importance of businesses and organizations securing their own databases, updating their software with regular patches, and monitoring the US Cybersecurity and Infrastructure Security Agency (CISA) for its Known Exploited Vulnerabilities (KEV) catalog. On August 27, 2026, CISA confirmed that CVE-2023-49105 was actively exploited and added a critical security flaw to its KEV catalog, likely in response to developments in the Philippines.

China-linked Cyber Espionage Campaign Targets Myanmar Government with a Malicious Backdoor

Researchers at Seqrite have released a report of a cyber intrusion campaign targeting the Government and Information Technology (IT) sector in Myanmar. The researchers believe that the threat actors are China-linked, based primarily on the recovered documents as well as assessment of targeted ministries, organizations, and individuals.

The campaign, officially tracked by the cybersecurity firm as “Operation QUICSILVER,” is said to have targeted Myanmar government personnel via targeted phishing attacks using files primarily written in the local Burmese language, and other legitimate-looking documents aimed at copying official government typography. 

A copy of the decoy document showing an official training or graduation related certificate. Photo from Seqrite, 2026

The decoys are used as an initial access for the exploit, in order to embed the backdoor “QUICAgent” to the victim system. This allows the threat actors to accomplish remote code execution (RCE) and establish persistent access for long term intelligence collection.

The decoys are used as an initial access for the exploit, in order to embed the backdoor “QUICAgent” to the victim system. This allows the threat actors to accomplish remote code execution (RCE) and establish persistent access for long term intelligence collection.

In a previous PSA Intelligence Cyber Risk report, a Pakistan-linked threat actor conducted a similar campaign against the Afghan government entities. The threat actor attempted to lure personnel from Afghanistan’s Ministry of Finance through the use of documents specifically created using the local Afghan language of Pashto.

PSA Intelligence notes that tactics like this are primarily aimed at mimicking the tempo, norms, and procedure of targeted organizations. Furthermore, this level of sophistication may also suggest careful and extensive reconnaissance against the organization, adding to the plausibility of state-sponsored cyber intrusion. 

China’s Strategic Interest and the Civil War in Myanmar

China’s involvement in the country grew significantly since the start of Myanmar’s civil war in 2021. China strengthened its relationship with Myanmar’s military junta primarily through economic investments, continued arms sales, and even direct military and security assistance to the government forces. 

Moreover, China’s cyber intrusion with a partner country perfectly captures China’s pattern of conducting peacetime reconnaissance and intelligence collection. Based on the recovered deleted file directory by the researchers at Seqrite, the majority of the suspected decoy documents include policy documents about Association of Southeast Asian Nations (ASEAN), as well as analysis on US-China relations. Due to this, PSA Intelligence assesses that China’s intelligence collection against Myanmar primarily serves to inform foreign and regional policy rather than an active attempt to compromise Myanmar’s government institutions. 

Cybersecurity Threat Landscape

AI Generated Disinformation Can Now Target Specific Cultures and Languages

Japan recently released its 2026 Defense White Paper, which emphasizes the growing role of Artificial Intelligence (AI) in information warfare and cyber influence operations. 

Separately, OpenAI disclosed cyber influence campaigns conducted by both actors believed to be based in Russia and China, revealing sophisticated efforts by state-linked actors to actively influence policy discussions abroad through the use of generative AI. 

The (Current) Anatomy of AI Enabled Influence Campaign

Recent case studies of cyber influence operations  targeting Europe, US, and Asia show that AI generated propaganda is nuanced to the target audience using relevant cultural narratives and written in native languages.  

Collection of AI generated contents featured on OpenAI reports. Photos by OpenAI, 2026

An analysis of the AI operations during elections in US, Canada, and Poland shows that AI-driven online discussion can significantly affect voter preferences. As such, there are two main identifying features by which AI-enabled cyber influence operations operates:

  • First, these AI networks operate under botnet-like operations. In a prior China and Russia-linked disinformation campaign, the cyber threat actors used AI and other online tools to automate the creation of bot farms, effectively deploying thousands of profiles on the internet. Furthermore, the threat actors used known AI tools to generate and fabricate names, images and other personally identifiable information in order to avoid bot detection and look more human. 
  • Second, the operations typically tend to establish relationships rather than reach. Highly sophisticated campaigns almost always target niche and specific communities, typically responding and interacting with the same topics and people alike. In the OpenAI report about the Russian AI-enabled influence campaign, the Russia-linked cyber threat actors deliberately fabricated fake think tanks along with fake research articles in order to establish legitimacy among the “expert community.”

PSA Intelligence notes that while influence operations are not exactly new, AI adds another dimension which can aggravate the risk of disinformation for the general public, most especially populations without Critical AI Literacy (CAIL).

The Brookings Institution created a six category breakout scale in order to measure real-world impact and spread of online influence operations and disinformation. Both OpenAI reports on China and Russia-linked campaigns place the events in Categories One to Three of the Breakout scale, which means that, at most, these influence operations can spread across multiple social media platforms and reach multiple distinct communities. 

A Series of Cyberattacks Targeting Healthcare Companies Conducted by a Single Cybercriminal Group

A wave of cyberattacks and data extortion campaigns recently targeted healthcare, pharmaceutical, and medical technology sectors in the United States (US). The attacks are defined by identity-driven social engineering (vishing), Single Sign-On (SSO) account takeovers, and data exfiltration from enterprise cloud and Software-as-a-Service (SaaS) environments such as Snowflake, Salesforce, and Amazon Web Services (AWS). 

Central to these attacks is the cybercriminal group known as ShinyHunters, operating alongside overlapping extortion groups. Their primary objective is financial monetization achieved by weaponizing sensitive Protected Health Information (PHI) and personally identifiable information (PII), using a “pay or leak” ultimatum tactic against target organizations. ShinyHunters is known to utilize “a mix of social engineering, identity abuse, and SaaS-focused data theft techniques” in their campaigns. 

Key Incident Breakdowns 

Recent Disclosures reveal that pharmaceutical distributors, data migration vendors, medical technology and device manufacturers were targeted by threat actors. 

  • McKesson Corporation (August 2026): Pharmaceutical distribution company McKesson disclosed an unauthorized intrusion into third-party applications affecting its Oncology and Multispeciality and Medical-Surgical business units. ShinyHunters claimed responsibility using voice phishing (vishing) and impersonation domains against employees as the entry point to compromise Okta Single Sign-On (SSO) credentials.
  • Novocure (August/September 2026): The oncology medical technology firm known for Tumor Treating Fields cancer therapies  disclosed an incident compromising patient records and employee data. ShinyHunters claimed responsibility for the attack and published a 33 GB archive of exfiltrated data on their data leak portal.
  • Aesto Health (Disclosed August/September 2026): Aesto Health, a vendor providing data migration and archiving solutions for Electronic Health Record (EHR) systems, confirmed that an intrusion into its AWS infrastructure compromised the information of patients across 29 covered healthcare entities. 
  • Boston Scientific (August/September 2026): Medical device manufacturer confirmed a cybersecurity incident affecting on-premise operational technology (OT). While details of the incident were not disclosed, the attack forced network shutdowns, disrupted device manufacturing, and halted global order processing and distribution. 
  • Sector-Wide Wave: These breaches coincide with attacks targeting Medtronic, DentaQuest, iRhythm, CareCloud, Unlimited Technology Systems, and Nutex Health, prompting alerts from the Health Information Sharing and Analysis Center (Health-ISAC)

What does this mean for the Philippines

The recent cyber incidents in the US highlight a vulnerability for the Philippines due to its status as a global hub for Information Technology and Business Process Management (IT-BPM). Because these outsourced services require connectivity to certain networks, the country is an attractive target for third-party supply chain attacks. Furthermore, this international threat mirrors ongoing vulnerabilities within the Philippines’ own domestic healthcare infrastructure. According to Viettel’s H1 2026 Threat Landscape Report, local institutions remain dangerously exposed due to a reliance on legacy on-premise servers, unsegmented networks, and a lack of dedicated Security Operations Center (SOC) capabilities.

A report by cybersecurity firm VulnCheck revealed that Chinese-manufactured commercial and enterprise routers by Zbtlink were discovered to have two pre-installed backdoors. Identified as “SPEAKINGSTONE” and “DARKLANTERN,” these vulnerabilities were found in models sold globally through commercial distributors and e-commerce platforms. If exploited, they allow unauthenticated remote attackers to execute commands and maintain persistent surveillance access to the targeted devices.

The report notes that Zbtlink white-labels its hardware under various brand names rather than just its own. In the Philippines, the affected hardware reportedly appears on the e-commerce platform Shopee under the “WORDFI” brand. 

White-labeled Zbtlink Router under DeepOrange brand in Amazon | Source: VulnCheck
White-labeled WORDFI router in Shopee

Zbtlink models found with the backdoors: 

  • Affected with DARKLANTERN: WE1326, WE2426-C, WE357, WE5926, WE5926-EC_QP, WE5926-WD, WE826-Q, WE826-T2, WE826-WD. WF3526-P, WG3526
  • Affected with SPEAKINGSTONE: WE826-T2, L3_VS_8, ZBT-7628, ZBT-ZBT7621

What Do the Backdoor Vulnerabilities Do?

Both vulnerabilities carry a Common Vulnerabilities Scoring System (CVSS) of 9.3 and operate without requiring authentication or interaction. SPEAKINGSTONE, identified as Common Vulnerability Exposure (CVE) 2026-74233, allows threat actors to completely bypass passwords by sending network packets that instantly run malicious commands with maximum system privileges. 

Meanwhile, DARKLANTERN, identified as CVE 2026-74233, is a spyware that connects to command servers in China. It constantly broadcasts network data (Wi-Fi passwords, connected device list, router hardware IDs) completely unencrypted while holding the connection open so threat actors can drop new malicious payloads onto the system at any time. 

Zbtlink representatives claimed that the identified backdoors were actually intended as “after-sales technical support tools”. The company stated that sales of the affected models and downloads for the relevant firmware have been removed from their official website, adding that they are working on updates to resolve the issue. 

Recommendations: 

The discovery of pre-installed backdoors in these devices underscores the national security risks embedded within the global technology supply chain. Much like the unauthorized data transmissions recently discovered in third-party UK drone cameras, these factory-installed router backdoors demonstrate how seemingly compliant commercial electronics can be exploited as covert devices for state espionage.

PSA Intelligence recommends that enterprise risk management teams handling sensitive or classified materials reassess their risk exposure to third-party vendors and procurement policies. Risk management teams who assess their business to be at high risk from espionage threats will benefit from involving security practitioners in the procurement process for equipment intended to safeguard sensitive or classified materials. 

More Readings: Chinese Implants in the Supply Chain | Analysis on UK Navy Drones Camera Sent Data Back to China

Cyber Risks to Monitor

TerminalFix Social Engineering Technique Uses Fake Verification Prompts to Compromise Systems

Microsoft released a warning against a variant of ClickFix called TerminalFix, which makes use of fake Cloudflare CAPTCHA prompts on compromised websites to paste malicious code into a command-line interface (CLI) such as Windows PowerShell.  As a reminder, a ClickFix is a type of social engineering technique used by threat actors to trick users into executing malicious code on their own systems. 

This type of attack differs from a typical ClickFix attack by directing users to paste malicious code into the Windows Run Box; it instructs users to paste the code into the CLI instead, giving the illusion of a legitimate IT support fix. 

Command-Line Interface (CLI) in Windows

The Lure

The TerminalFix campaign gains initial access by showing victims a highly convincing fake Cloudflare “Verify you are human” CAPTCHA overlay on a compromised website.  Interacting with this prompt silently copies a malicious script to the victim’s clipboard. On-screen instructions then direct them to paste (Ctrl + V) and run this code on the CLI, starting the multi-staged attack chain. 

Fake CloudFlare Verification Turnstile. Source: The Hacker News, 2026

What Makes a TerminalFix More Dangerous? 

Standard ClickFix attacks typically target Operating System (OS) Run dialogs (Win+R in Windows, Cmd+Space in macOS, Ctrl+Alt+T in Ubuntu), which restricts them to short commands due to strict character limits. However, by tricking users into pasting code directly into a CLI, threat actors bypass these constraints, which allow them to execute “more complex, multi-line scripts.”  Once initial access and code execution are achieved, threat actors launch a multi-stage attack chain involving Dynamic Link Library (DLL) sideloading, steganographic extraction, and reconnaissance - ultimately aiming to establish persistent access and move across the network. 

TerminalFix Attack Chain. Source: Microsoft, 2026

Recommendations

PSA Intelligence advises clients to remain vigilant against social engineering attacks by carefully verifying website URLs to ensure they match official domains before interacting with any security or verification prompts. Additionally, it is important to remember that legitimate verification, such as Cloudflare, typically only require clicking a checkbox and never the execution of system commands. If you encounter suspicious verification requests or unusual device errors when visiting a website, stop interacting with the page immediately and contact your IT support team for further guidance.

More Reading: TerminalFix campaign deploys a reverse tunnel through multistage intrusion

Subscribe to CyberSecurity.PH

Subscribe to receive our latest updates as they get released.
[email protected]
Subscribe