Exposed WordPress Backups: A Breeding Ground for Credential Theft
Recent investigations have uncovered a tool known as TIKTOUK, which exploits exposed WordPress backups, yielding a trove of cloud and email credentials that have become enticing targets for cybercriminals.
The TIKTOUK toolkit employs a multifaceted approach, capitalizing on various techniques to scrutinize websites for sensitive configurations, recapture stored passwords, and siphon secret data from JavaScript loaded for site visitors. This operation was already in full swing when researchers noticed its prevalence.
A leaked control panel revealed a staggering cache of approximately 50,000 server-side credentials across around 37,000 domains, featuring hundreds of validated AWS keys that were active.
LevelBlue’s researchers pinpointed this alarming toolkit through source code analysis, deconstruction, and focused testing.
In a report disseminated to Cyber Security News, LevelBlue elaborated on how this tool amalgamates WordPress reconnaissance, configuration extraction, password recovery, and JavaScript analysis.
These findings serve as a stark reminder that a neglected backup can pose risks beyond mere database exposure.
Equivalent instances of publicly available repositories have similarly exposed critical cloud keys and proprietary documents, underscoring how seemingly innocuous development artifacts can amplify security oversights.
TIKTOUK’s Operations and Components
The TIKTOUK toolkit comprises two Python components and a Go-based Linux crawler, each tasked with fetching jobs from a central HTTP service, subsequently relaying their findings or status updates back.
This service orchestrates the distribution of targets and the collection of data, albeit the tests have yet to confirm an automatic transition between components.
The probing component initiates its work by identifying WordPress websites, employing REST batch requests that marry malformed URLs with operations designed for deletion and paragraph rendering.
When initial JSON requests yield forbidden responses, the system retries utilizing multipart encoding, often with successful outcomes, thereby creating a distinct sequence for defenders to analyze.
Meanwhile, a separate collection component targets exposed WordPress configuration backups, extracting crucial database credentials and security keys.
It also probes for environment settings, repository configurations, backed-up databases, and debug logs, seeking out credentials that are unintentionally left open to typical web traffic.
This process includes nested batch requests to glean database option values by first querying for the options table name and later utilizing that name in follow-up inquiries.
Hexadecimal responses are decoded into plaintext, prepping records that encapsulate database specifics, email credentials, AWS key pair configurations, and API key templates.
The implications reach far beyond a single site. The leaked AWS keys uncovered possess the potential for misuse across email services, computing resources, and AI functionalities.
Previous analyses of active AWS credentials highlighted that compromised keys can retain powerful access long after they have been publicly exposed.
Password Recovery and Threat Detection
The toolkit’s collector adeptly supports encrypted configurations from various applications, including WP Mail SMTP, Easy WP SMTP, and FluentSMTP, affirming its ability to retrieve plaintext credentials leveraging the requisite encryption keys or WordPress configuration data.
This achievement does not signify a breakthrough against encryption but reveals that the toolkit has the necessary intelligence to unlock safeguarded settings.
Specifically, the collector can derive an email password for Amazon SES from provided AWS secrets, effectively transforming the cloud key data into legitimate email service credentials.
The JavaScript crawler fetches pages and corresponding scripts, analyzing their contents and forwarding significant matches back to the central hub.
Noteworthy findings uncovered patterns linked with major players such as SendGrid, Anthropic, Bedrock, and AWS.
The threat landscape closely mirrors the Beacon cloud credential breach, where an AWS key embedded in public JavaScript facilitated database theft.
LevelBlue has indicated a connection between TIKTOUK’s request structures and vulnerabilities such as CVE-2026-60137 and CVE-2026-63030, although there was no evidence furnished this would lead to successful exploitation.
Simulation experiments returned prepared responses without executing any SQL commands. In parallel, telemetry data indicated successful payload retrieval and control communication, while related investigations identified a corresponding Go botnet capable of remote command execution.
The advisory cautions that affected WordPress versions include 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2.
The laboratory results confirm component behavior but do not validate the collection of stolen credentials during simulated runs, nor do they demonstrate exploitation of a live WordPress installation.
Defenders are encouraged to correlate observed unusual batch requests, alterations in request encoding, access to sensitive files, and resultant submissions as part of their investigative strategy.

LevelBlue advises cross-referencing hashes alongside HTTP activity and verifying incidents against local logs, emphasizing that singular paths or parameters in isolation are insufficient indicators of malicious intent.
Indicators of Compromise (IoCs):
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | c6b8d0cdb53da98a5d15e79b7bb9e9f4c272c4f9592acdc291089f126f892f45 | WordPress probing component. |
| SHA-256 | 0d8ea89a63070f68286249aa437aece0e040c1609b8c5c0950ebbc90e6f70f02 | Credential-collection component. |
| SHA-256 | 1e22fde68d3277ed0fe7a8a7b554f0ae118260a2fa143f8e1bdc84c994ebbe90 | JavaScript secret scanner. |
| SHA-1 | 9903f4576980ff7cfd560ca57c665a4b59b3c30d | Related Go botnet binary with remote command execution capability. |
| IP Address | 193.32.162[.]134 | Additional TIKTOUK control panel. |
| IP Address | 195.178.110[.]209 | Additional TIKTOUK control panel. |
| IP Address | 31.56.58[.]59 | Payload host and controller identified in telemetry. |
| File Name | wp2s_poll.py | Python component for probing WordPress targets. |
| File Name | wp2s_crack.py | Python component focused on credential collection. |
| File Name | jscrawl-amd64 | Go-based Linux executable scanning JavaScript for secrets. |
| Targeted File | wp-config.php.bak | Exposed WordPress configuration backup. |
| Targeted File | .env | Environment configuration file. |
| Targeted File Path | .git/config | Repository configuration file. |
| REST Request Path | /wp/v2/categories/0 | Targeted route with DELETE operation. |
| REST Request Path | /wp/v2/block-renderer/core/paragraph | Targeted route with POST operation. |
| Reporting Endpoint | /v1/ingest | Endpoint receiving findings from probing. |
Source link: Cybersecuritynews.com.



