TIKTOUK Toolkit Collects WordPress, Email, and Cloud Credentials

Summary
LevelBlue analyzes TIKTOUK, a toolkit that probes WordPress, retrieves exposed configuration and plugin settings to recover email credentials, and scans JavaScript for secrets. Telemetry and a leaked panel indicate active, large-scale credential collection.
Key points
- TIKTOUK’s two Python components and Go-based Linux crawler receive tasks from a central hub and send back collected data.
- The toolkit probes WordPress REST routes, searches for exposed configuration and backup files, and uses available keys to decrypt settings from WP Mail SMTP, Easy WP SMTP, and FluentSMTP.
- Its crawler scans referenced JavaScript for secret-like values, including AWS-shaped credentials and SendGrid, Anthropic, and Bedrock token patterns.
- LevelBlue telemetry linked a victim host to payload delivery and command-and-control at 31.56[.]58[.]59. A leaked panel showed about 50,000 server-side credentials across roughly 37,000 domains, including hundreds of actor-validated live AWS keys.
- The analysis cites CVE-2026-60137 and CVE-2026-63030 as context for the WordPress request patterns, but successful exploitation was not demonstrated in the controlled tests.
- LevelBlue reports additional TIKTOUK panels at 193.32.162[.]134 and 195.178.110[.]209, and identified a related Go-compiled botnet binary with remote command execution capability.
Article Details
- Attack Vectors
- wp2s_poll.py probed WordPress pages and REST batch routes using a malformed http://: path alongside DELETE and POST operations. After HTTP 403 responses to JSON requests, it retried with multipart encoding and received HTTP 200.
- wp2s_crack.py requested exposed wp-config.php.bak, .env, .git/config, backup.sql, and wp-content/debug.log files, and used nested REST batch requests containing author_exclude and UNION ALL SELECT expressions to request database option values.
- wp2s_crack.py used available keys and WordPress configuration material to recover plaintext email credentials from WP Mail SMTP, Easy WP SMTP, and FluentSMTP settings. It also derived an SES SMTP password from a supplied AWS secret.
- jscrawl-amd64 fetched pages and referenced JavaScript files, then scanned their contents for secret patterns.
- The components submitted collected findings to a hub through /v1/ingest or /api/crack/report. Incident telemetry separately identified a payload host that continued to operate as a controller.
- Defensive Notes
- Investigate REST batch requests containing http://: with nested author_exclude or UNION expressions, particularly when JSON requests are followed by multipart requests.
- Correlate requests for configuration, backup, environment, repository, and log files with subsequent result submissions from the same process or host.
- Use sample hashes for file identification and investigate matching executions alongside HTTP activity; /v1/ingest and /api/crack/report are contextual features, not standalone proof of malicious activity.
- The controlled executions used synthetic target data and prepared responses. They did not demonstrate successful exploitation of either cited CVE, a live-site breach, valid stolen credentials, or an automatic handoff between components.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 193[.]32[.]162[.]134 | Additional TIKTOUK C2 panel identified by LevelBlue. |
| IPV4 | 195[.]178[.]110[.]209 | Additional TIKTOUK C2 panel identified by LevelBlue. |
| IPV4 | 31[.]56[.]58[.]59 | Payload host identified in the IOC section; incident telemetry described the same host as a controller with which the victim continued communicating. |
| SHA1 | 9903f4576980ff7cfd560ca57c665a4b59b3c30d | Hash of a related Golang-compiled botnet binary reported to have remote command execution capability. |
| SHA256 | 0d8ea89a63070f68286249aa437aece0e040c1609b8c5c0950ebbc90e6f70f02 | Hash of the analyzed wp2s_crack.py credential-collection component. |
| SHA256 | 1e22fde68d3277ed0fe7a8a7b554f0ae118260a2fa143f8e1bdc84c994ebbe90 | Hash of the analyzed jscrawl-amd64 JavaScript secret scanner. |
| SHA256 | c6b8d0cdb53da98a5d15e79b7bb9e9f4c272c4f9592acdc291089f126f892f45 | Hash of the analyzed wp2s_poll.py WordPress probing component. |
MITRE ATT&CK
T1041 · Exfiltration Over C2 ChannelThe components submitted collected findings, including recovered plaintext credentials, to their tasking and reporting hub through /v1/ingest or /api/crack/report.T1190 · Exploit Public-Facing Applicationwp2s_crack.py sent nested REST batch requests with author_exclude and UNION ALL SELECT expressions to request database option values; successful exploitation of the cited vulnerabilities was not demonstrated.T1552.001 · Credentials In Fileswp2s_crack.py requested exposed configuration, environment, repository, backup, and log files and extracted credential material from returned data.T1595.002 · Vulnerability Scanningwp2s_poll.py probed WordPress sites and REST batch-route behavior, classified targets, and retried requests using multipart encoding after JSON requests returned HTTP 403.
CVE
CVE-2026-60137CVE-2026-60137 describes insufficient sanitization of the author__not_in parameter in WP_Query, enabling SQL injection when untrusted input reaches that parameter.CVE-2026-63030CVE-2026-63030 describes REST batch-route confusion that can be combined with the SQL injection to achieve remote code execution (RCE).
Products
Easy WP SMTPReverse engineering of wp2s_crack.py identified separate decoding routines for WP Mail SMTP, Easy WP SMTP, and FluentSMTP settings.FluentSMTPReverse engineering of wp2s_crack.py identified separate decoding routines for WP Mail SMTP, Easy WP SMTP, and FluentSMTP settings.WordPressTIKTOUK brings together WordPress probing, collection of exposed configuration data, recovery of encrypted email credentials, and JavaScript secret scanning.WP Mail SMTPReverse engineering of wp2s_crack.py identified separate decoding routines for WP Mail SMTP, Easy WP SMTP, and FluentSMTP settings.