LevelBlue SpiderLabs has detailed TIKTOUK, a three-part toolkit that probes WordPress sites, harvests exposed configuration files, and decrypts stored email credentials.
It sends the results to a central hub. A leaked control panel reportedly held about 50,000 server-side credentials across roughly 37,000 domains.
SpiderLabs researcher Maor Gabay says the toolkit combines WordPress probing, configuration-data collection, recovery of encrypted email credentials, and JavaScript secret scanning.
TIKTOUK Toolkit Steals WordPress Credentials, AWS Keys and SMTP Logins
It has three components. Two are Python scripts, wp2s_poll.py and wp2s_crack.py. The third is jscrawl-amd64, a Go-based Linux crawler. Each one pulls its own tasks from the hub and reports structured results back to it.
wp2s_poll.py fetches a target list and identifies WordPress sites. It then sends REST batch requests containing the malformed path http://:. Each batch pairs a DELETE operation against /wp/v2/categories/0 with a POST operation against /wp/v2/block-renderer/core/paragraph.
When JSON requests returned HTTP 403, the component retried with multipart encoding and received HTTP 200. Defenders can use that JSON-then-multipart sequence as a detection lead. The script also searches page content for exposed secrets.
wp2s_crack.py requests wp-config.php.bak and parses database credentials and WordPress key material from it. It also sends nested REST batch requests carrying author_exclude and UNION ALL SELECT expressions to pull option values from the database.
It then requests .env, .git/config, backup.sql and wp-content/debug.log. Results included database configuration, SMTP records, AWS credential pairs and API key patterns.
The toolkit has dedicated decryption routines for three WordPress SMTP plugins:
| Plugin | Method |
|---|---|
| WP Mail SMTP | XSalsa20-Poly1305 secretbox decryption |
| Easy WP SMTP | AES-256-CTR, key derived via SHA-256 |
| FluentSMTP | AES-256-CTR using LOGGED_IN_KEY, then removal of the LOGGED_IN_SALT suffix |
Gabay stresses that this is credential recovery using available keys, not a break of the encryption itself. The component can also derive an Amazon SES SMTP password from an AWS secret.
The third component, jscrawl-amd64, scans JavaScript files for secrets. Its findings included SendGrid, Anthropic and Bedrock token patterns, plus AWS-shaped credential pairs.
The request structures resemble two WordPress advisories. CVE-2026-60137 covers SQL injection through the author__not_in parameter in WP_Query.
CVE-2026-63030 covers REST batch-route confusion that can be chained with that SQL injection to reach remote code execution.
It affects WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2. The analysis did not demonstrate successful exploitation of either flaw. The test simulator returned prepared responses and ran no SQL.
LevelBlue analyst Ben Lee observed a victim host retrieving payloads from 31.56[.]58.59, which then acted as the controller. Analyst Leon Cottrell examined a leaked panel showing about 50,000 credentials across about 37,000 domains.
It included hundreds of actor-validated live AWS keys with SES, EC2 and Bedrock abuse potential. Additional panels sit at 193.32.162[.]134 and 195.178.110[.]209. Investigators also linked a Go-compiled botnet binary with remote command execution capability.
The lab runs used synthetic data and an analyst-controlled hub. They show component behavior, not a live-site breach.
Detection and Indicators
Defenders should correlate several signals rather than rely on any single path or parameter:
- REST batch requests containing
http://:with nestedauthor_excludeor UNION expressions. - Requests for backup, environment and config files, followed by outbound result submissions.
- Traffic to
/v1/ingestand/api/crack/report, judged alongside payload and sample identity.
| Indicator | Value |
|---|---|
| wp2s_poll.py SHA-256 | c6b8d0cdb53da98a5d15e79b7bb9e9f4c272c4f9592acdc291089f126f892f45 |
| wp2s_crack.py SHA-256 | 0d8ea89a63070f68286249aa437aece0e040c1609b8c5c0950ebbc90e6f70f02 |
| jscrawl-amd64 SHA-256 | 1e22fde68d3277ed0fe7a8a7b554f0ae118260a2fa143f8e1bdc84c994ebbe90 |
| Go botnet SHA-1 | 9903f4576980ff7cfd560ca57c665a4b59b3c30d |
| C2 panels | 193.32.162[.]134, 195.178.110[.]209 |
| Payload host | 31.56.58[.]59 |
Site owners should remove stray backup, .env and log files from web roots. They should also rotate any exposed keys and credentials, and patch WordPress to the fixed versions.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.