Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials
LevelBlue exposed the TIKTOUK toolkit harvesting ~50,000 credentials from 37,000 domains via exposed WordPress backups, including active AWS keys.
LevelBlue researchers identified a credential-harvesting toolkit called TIKTOUK comprising two Python components and a Go crawler that target exposed WordPress configuration backups, recover SMTP plugin passwords, and scan JavaScript for secrets. A leaked control panel contained roughly 50,000 real server-side credentials across about 37,000 domains, including hundreds of validated AWS keys. The toolkit decrypts WP Mail SMTP, Easy WP SMTP, and FluentSMTP settings and can derive Amazon SES passwords from AWS secrets. LevelBlue linked request structures to CVE-2026-60137 and CVE-2026-63030 but did not demonstrate successful exploitation; a related Go botnet with remote command execution capability was also identified.
- Leaked control panel held ~50,000 credentials across ~37,000 domains, including validated AWS keys
- Toolkit parses exposed WordPress backups, env files, and database logs for secrets
- Recovers plaintext credentials from WP Mail SMTP, Easy WP SMTP, and FluentSMTP plugins
- JavaScript scanner targets SendGrid, Anthropic, Bedrock, and AWS key patterns
- Request structures linked to CVE-2026-60137 and CVE-2026-63030 without confirmed exploitation
Vulnerabilities mentionedAll →
- CVE-2026-630309.810%WordPress Core Route Confusion (wp2shell) Enables SQL Injection to RCEpublished · WordPress Core KEV PoC ×4+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| sha1 | 9903f4576980ff7cfd560ca57c665a4b59b3c30d | a2fa143f8e1bdc84c994ebbe90 JavaScript secret scanner. SHA-1 9903f4576980ff7cfd560ca57c665a4b59b3c30d Related Go botnet binary with remote command execution capa |
| sha256 | 0d8ea89a63070f68286249aa437aece0e040c1609b8c5c0950ebbc90e6f70f02 | 2acdc291089f126f892f45 WordPress probing component. SHA-256 0d8ea89a63070f68286249aa437aece0e040c1609b8c5c0950ebbc90e6f70f02 Credential-collection component. SHA-256 1e22fde68d3277ed0f |
| sha256 | 1e22fde68d3277ed0fe7a8a7b554f0ae118260a2fa143f8e1bdc84c994ebbe90 | 0950ebbc90e6f70f02 Credential-collection component. SHA-256 1e22fde68d3277ed0fe7a8a7b554f0ae118260a2fa143f8e1bdc84c994ebbe90 JavaScript secret scanner. SHA-1 9903f4576980ff7cfd560ca57c |
| sha256 | c6b8d0cdb53da98a5d15e79b7bb9e9f4c272c4f9592acdc291089f126f892f45 | s of compromise (IoCs):- Type Indicator Description SHA-256 c6b8d0cdb53da98a5d15e79b7bb9e9f4c272c4f9592acdc291089f126f892f45 WordPress probing component. SHA-256 0d8ea89a63070f68286249 |
Full article961 words · extracted from cybersecuritynews.com · click to collapse
Exposed WordPress backups have become a valuable source of cloud and email credentials for attackers using a toolkit called TIKTOUK.
Rather than relying on one technique, its components search websites for sensitive files, recover stored passwords, and collect secrets from JavaScript delivered to visitors. The operation was already active at scale when researchers first observed it.
A leaked control panel contained approximately 50,000 real server-side credentials across about 37,000 domains, including hundreds of AWS keys that the attackers had validated as active. LevelBlue researchers identified the toolkit through source review, reverse engineering, and controlled testing.
LevelBlue said in a report shared with Cyber Security News (CSN) that its components combined WordPress probing, exposed configuration collection, email password recovery, and JavaScript scanning.
The findings highlight how a forgotten backup can expose more than a website database. Similar publicly exposed repository secrets have revealed cloud keys and sensitive business records, showing how accessible development material can widen an otherwise limited security mistake.
Exposed WordPress Backups
TIKTOUK uses two Python components and a Linux crawler written in Go. Each retrieves tasks from a central HTTP service and returns findings or status reports.
The service coordinates target distribution and collection, although the tests did not establish an automatic handoff between components.
The probing component first retrieves targets and identifies WordPress sites. It then sends REST batch requests combining a malformed URL with delete and paragraph-rendering operations.
When JSON requests received forbidden responses, it retried using multipart encoding and received successful responses, giving defenders a distinctive sequence to investigate.
A separate collection component retrieves an exposed WordPress configuration backup and extracts database credentials and security keys.
It also requests environment settings, repository configuration, database backups, and debug logs, looking for credentials left accessible through ordinary web requests.
Nested batch requests contain expressions designed to retrieve database option values. The component first requests the options table name, then uses the returned name in subsequent queries.
It decodes hexadecimal responses into text and prepares records containing database settings, email credentials, AWS key pairs, and API key patterns.
The cloud risk extends beyond the original website. The leaked panel included AWS keys with potential for abuse involving email delivery, computing resources, and AI services.
Earlier reporting on still active AWS credentials likewise showed how exposed keys can retain powerful access long after disclosure.
Password Recovery And Detection
The collector supports encrypted settings from WP Mail SMTP, Easy WP SMTP, and FluentSMTP. Researchers verified that it recovered plaintext credentials using the corresponding encryption keys or WordPress configuration material.
This was not a breakthrough against encryption: the toolkit obtained the information needed to unlock protected settings. Controlled checks also showed that supported decryption worked without optional cryptographic libraries.
The collector could derive an Amazon SES email password from a supplied AWS secret, turning cloud key material into credentials suitable for the email service.
The JavaScript crawler fetches pages and referenced scripts, scans their contents, and sends matches to the hub. Findings included patterns associated with SendGrid, Anthropic, Bedrock, and AWS.
The danger resembles the Beacon cloud credential breach, where an AWS key exposed in public JavaScript enabled database theft.
LevelBlue linked the request structures to CVE-2026-60137 and CVE-2026-63030, but did not demonstrate successful exploitation.
Controlled targets returned prepared responses without executing SQL. Separately, incident telemetry confirmed payload retrieval and controller communication, while investigators identified a related Go botnet with remote command execution capability.
The batch-route advisory identifies affected WordPress 6.9.x versions before 6.9.5 and 7.0.x versions before 7.0.2. Laboratory results establish component behavior, not a confirmed live-site breach.
They do not independently validate stolen credentials collected during simulated executions or demonstrate successful exploitation against a real WordPress installation in production.
Defenders should correlate unusual batch requests, changes in request encoding, sensitive-file access, and subsequent result submissions.
LevelBlue recommends checking sample hashes alongside HTTP activity and confirming incidents against local records. Individual paths or parameters alone do not establish malicious activity.
Indicators of compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.