TIKTOUK: Tracing a WordPress Credential Collection Toolkit

TIKTOUK: Tracing a WordPress Credential Collection Toolkit
TIKTOUK combines WordPress probing, exposed configuration harvesting, encrypted email credential recovery, and JavaScript secret scanning through three coordinated components that report to a central hub. The campaign also operated at scale with a leaked panel showing tens of thousands of credentials and included related infrastructure such as 31.56.58.59, 193.32.162.134, and 195.178.110.209. #TIKTOUK #LevelBlue #WordPress #SendGrid #Anthropic #Bedrock #AWS

Keypoints

  • TIKTOUK uses three components: wp2s_poll.py for WordPress probing, wp2s_crack.py for configuration and credential collection, and jscrawl-amd64 for JavaScript secret scanning.
  • All components retrieve tasks from a central HTTP hub and submit collected results and status updates back to it.
  • wp2s_poll.py probes WordPress pages and REST batch routes, including malformed and nested requests, then records classifications and secret-pattern matches.
  • wp2s_crack.py extracts data from exposed files such as wp-config.php.bak, .env, .git/config, backup.sql, and wp-content/debug.log, then recovers plaintext credentials from encrypted plugin settings.
  • The credential decoder supports WP Mail SMTP, Easy WP SMTP, and FluentSMTP, using supplied keys or WordPress configuration material to decrypt stored secrets.
  • jscrawl-amd64 fetches referenced JavaScript files and scans them for secret-like values, including SendGrid, Anthropic, Bedrock, and AWS-shaped credentials.
  • The report references WordPress advisories CVE-2026-60137 and CVE-2026-63030, but says successful exploitation was not demonstrated in the analysis.

MITRE Techniques

  • [T1190] Exploit Public-Facing Application – WordPress REST and query handling were probed with crafted requests and nested expressions to test for injection and route confusion (‘malformed path http://: together with a DELETE operation … and a POST operation …’; ‘nested author_exclude and UNION ALL SELECT expressions’).
  • [T1083] File and Directory Discovery – The collector requested exposed files and directories such as configuration, backup, environment, repository, and log files (‘retrieved wp-config.php.bak’; ‘requested .env, .git/config, backup.sql, and wp-content/debug.log’).
  • [T1005] Data from Local System – The component extracted database credentials, WordPress keys, SMTP records, AWS credential pairs, and API key patterns from returned data (‘parsed database credentials and WordPress key material’; ‘result messages contained database configuration, SMTP records, AWS credential pairs, and API key patterns’).
  • [T1027] Obfuscated Files or Information – The parser decoded hexadecimal values wrapped in markers to recover usable text (‘decoded hexadecimal values enclosed by ||| markers into text’).
  • [T1552] Unsecured Credentials – Exposed configuration and backup material was used to recover plaintext email credentials and other secrets (‘the collection component used the corresponding keys to recover plaintext email credentials’; ‘retrieved wp-config.php.bak’).
  • [T1555] Credentials from Password Stores – Encrypted plugin settings were decrypted to recover stored SMTP credentials (‘recovered the expected plaintext for all three formats’).
  • [T1105] Ingress Tool Transfer – The payloads and tasks were retrieved from a controller/hub and results were sent back over HTTP (‘Each component retrieved its own tasks from the hub’; ‘submitted findings to /v1/ingest’).
  • [T1210] Exploitation of Remote Services – The analysis describes remote tasking and command/control interactions with infrastructure used to deliver payloads and collect results (‘the victim host retrieved the payloads from 31.56[.]58.59 and continued communicating with the same host’).

Indicators of Compromise

  • [IP address] controller and payload infrastructure – 31.56.58.59, 193.32.162.134, and 195.178.110.209
  • [File names] analyzed sample names – wp2s_poll.py, wp2s_crack.py, jscrawl-amd64, and a Golang-compiled botnet binary
  • [URLs / API paths] collection and reporting endpoints – /v1/ingest, /api/crack/report, and /wp/v2/block-renderer/core/paragraph
  • [Configuration / backup files] exposed data sources queried for secrets – wp-config.php.bak, .env, .git/config, backup.sql, and wp-content/debug.log
  • [Domains / target lists] tasking and target distribution artifacts – target domains and WordPress sites collected through the hub, plus 37k domains referenced in the leaked panel
  • [Hashes] sample identification references – file hashes were mentioned for the analyzed samples and archive, with 2+ hashes referenced but not enumerated in the source


Read more: https://www.levelblue.com/blogs/spiderlabs-blog/tiktouk-tracing-a-wordpress-credential-collection-toolkit