TIKTOUK Toolkit Collects WordPress, Email, and Cloud Credentials

· Original article ↗

Summary

LevelBlue analyzes TIKTOUK, a toolkit that probes WordPress, retrieves exposed configuration and plugin settings to recover email credentials, and scans JavaScript for secrets. Telemetry and a leaked panel indicate active, large-scale credential collection.

Key points

  • TIKTOUK’s two Python components and Go-based Linux crawler receive tasks from a central hub and send back collected data.
  • The toolkit probes WordPress REST routes, searches for exposed configuration and backup files, and uses available keys to decrypt settings from WP Mail SMTP, Easy WP SMTP, and FluentSMTP.
  • Its crawler scans referenced JavaScript for secret-like values, including AWS-shaped credentials and SendGrid, Anthropic, and Bedrock token patterns.
  • LevelBlue telemetry linked a victim host to payload delivery and command-and-control at 31.56[.]58[.]59. A leaked panel showed about 50,000 server-side credentials across roughly 37,000 domains, including hundreds of actor-validated live AWS keys.
  • The analysis cites CVE-2026-60137 and CVE-2026-63030 as context for the WordPress request patterns, but successful exploitation was not demonstrated in the controlled tests.
  • LevelBlue reports additional TIKTOUK panels at 193.32.162[.]134 and 195.178.110[.]209, and identified a related Go-compiled botnet binary with remote command execution capability.

Article Details

Attack Vectors
  • wp2s_poll.py probed WordPress pages and REST batch routes using a malformed http://: path alongside DELETE and POST operations. After HTTP 403 responses to JSON requests, it retried with multipart encoding and received HTTP 200.
  • wp2s_crack.py requested exposed wp-config.php.bak, .env, .git/config, backup.sql, and wp-content/debug.log files, and used nested REST batch requests containing author_exclude and UNION ALL SELECT expressions to request database option values.
  • wp2s_crack.py used available keys and WordPress configuration material to recover plaintext email credentials from WP Mail SMTP, Easy WP SMTP, and FluentSMTP settings. It also derived an SES SMTP password from a supplied AWS secret.
  • jscrawl-amd64 fetched pages and referenced JavaScript files, then scanned their contents for secret patterns.
  • The components submitted collected findings to a hub through /v1/ingest or /api/crack/report. Incident telemetry separately identified a payload host that continued to operate as a controller.
Defensive Notes
  • Investigate REST batch requests containing http://: with nested author_exclude or UNION expressions, particularly when JSON requests are followed by multipart requests.
  • Correlate requests for configuration, backup, environment, repository, and log files with subsequent result submissions from the same process or host.
  • Use sample hashes for file identification and investigate matching executions alongside HTTP activity; /v1/ingest and /api/crack/report are contextual features, not standalone proof of malicious activity.
  • The controlled executions used synthetic target data and prepared responses. They did not demonstrate successful exploitation of either cited CVE, a live-site breach, valid stolen credentials, or an automatic handoff between components.

Indicators of compromise

TypeIndicatorContext
IPV4193[.]32[.]162[.]134Additional TIKTOUK C2 panel identified by LevelBlue.
IPV4195[.]178[.]110[.]209Additional TIKTOUK C2 panel identified by LevelBlue.
IPV431[.]56[.]58[.]59Payload host identified in the IOC section; incident telemetry described the same host as a controller with which the victim continued communicating.
SHA19903f4576980ff7cfd560ca57c665a4b59b3c30dHash of a related Golang-compiled botnet binary reported to have remote command execution capability.
SHA2560d8ea89a63070f68286249aa437aece0e040c1609b8c5c0950ebbc90e6f70f02Hash of the analyzed wp2s_crack.py credential-collection component.
SHA2561e22fde68d3277ed0fe7a8a7b554f0ae118260a2fa143f8e1bdc84c994ebbe90Hash of the analyzed jscrawl-amd64 JavaScript secret scanner.
SHA256c6b8d0cdb53da98a5d15e79b7bb9e9f4c272c4f9592acdc291089f126f892f45Hash of the analyzed wp2s_poll.py WordPress probing component.

MITRE ATT&CK

CVE

Products

Tools

Related Articles