Unsecured WordPress Backups Revealed Valuable AWS and Email Credentials

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

Exposed WordPress Backups: A Breeding Ground for Credential Theft

Recent investigations have uncovered a tool known as TIKTOUK, which exploits exposed WordPress backups, yielding a trove of cloud and email credentials that have become enticing targets for cybercriminals.

The TIKTOUK toolkit employs a multifaceted approach, capitalizing on various techniques to scrutinize websites for sensitive configurations, recapture stored passwords, and siphon secret data from JavaScript loaded for site visitors. This operation was already in full swing when researchers noticed its prevalence.

A leaked control panel revealed a staggering cache of approximately 50,000 server-side credentials across around 37,000 domains, featuring hundreds of validated AWS keys that were active.

LevelBlue’s researchers pinpointed this alarming toolkit through source code analysis, deconstruction, and focused testing.

In a report disseminated to Cyber Security News, LevelBlue elaborated on how this tool amalgamates WordPress reconnaissance, configuration extraction, password recovery, and JavaScript analysis.

These findings serve as a stark reminder that a neglected backup can pose risks beyond mere database exposure.

Equivalent instances of publicly available repositories have similarly exposed critical cloud keys and proprietary documents, underscoring how seemingly innocuous development artifacts can amplify security oversights.

TIKTOUK’s Operations and Components

The TIKTOUK toolkit comprises two Python components and a Go-based Linux crawler, each tasked with fetching jobs from a central HTTP service, subsequently relaying their findings or status updates back.

This service orchestrates the distribution of targets and the collection of data, albeit the tests have yet to confirm an automatic transition between components.

The probing component initiates its work by identifying WordPress websites, employing REST batch requests that marry malformed URLs with operations designed for deletion and paragraph rendering.

When initial JSON requests yield forbidden responses, the system retries utilizing multipart encoding, often with successful outcomes, thereby creating a distinct sequence for defenders to analyze.

Meanwhile, a separate collection component targets exposed WordPress configuration backups, extracting crucial database credentials and security keys.

It also probes for environment settings, repository configurations, backed-up databases, and debug logs, seeking out credentials that are unintentionally left open to typical web traffic.

This process includes nested batch requests to glean database option values by first querying for the options table name and later utilizing that name in follow-up inquiries.

Hexadecimal responses are decoded into plaintext, prepping records that encapsulate database specifics, email credentials, AWS key pair configurations, and API key templates.

The implications reach far beyond a single site. The leaked AWS keys uncovered possess the potential for misuse across email services, computing resources, and AI functionalities.

Previous analyses of active AWS credentials highlighted that compromised keys can retain powerful access long after they have been publicly exposed.

Password Recovery and Threat Detection

The toolkit’s collector adeptly supports encrypted configurations from various applications, including WP Mail SMTP, Easy WP SMTP, and FluentSMTP, affirming its ability to retrieve plaintext credentials leveraging the requisite encryption keys or WordPress configuration data.

This achievement does not signify a breakthrough against encryption but reveals that the toolkit has the necessary intelligence to unlock safeguarded settings.

Specifically, the collector can derive an email password for Amazon SES from provided AWS secrets, effectively transforming the cloud key data into legitimate email service credentials.

The JavaScript crawler fetches pages and corresponding scripts, analyzing their contents and forwarding significant matches back to the central hub.

Noteworthy findings uncovered patterns linked with major players such as SendGrid, Anthropic, Bedrock, and AWS.

The threat landscape closely mirrors the Beacon cloud credential breach, where an AWS key embedded in public JavaScript facilitated database theft.

LevelBlue has indicated a connection between TIKTOUK’s request structures and vulnerabilities such as CVE-2026-60137 and CVE-2026-63030, although there was no evidence furnished this would lead to successful exploitation.

Simulation experiments returned prepared responses without executing any SQL commands. In parallel, telemetry data indicated successful payload retrieval and control communication, while related investigations identified a corresponding Go botnet capable of remote command execution.

The advisory cautions that affected WordPress versions include 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2.

The laboratory results confirm component behavior but do not validate the collection of stolen credentials during simulated runs, nor do they demonstrate exploitation of a live WordPress installation.

Defenders are encouraged to correlate observed unusual batch requests, alterations in request encoding, access to sensitive files, and resultant submissions as part of their investigative strategy.

A magnifying glass over the word INVESTIGATE on a wooden desk with office supplies nearby.

LevelBlue advises cross-referencing hashes alongside HTTP activity and verifying incidents against local logs, emphasizing that singular paths or parameters in isolation are insufficient indicators of malicious intent.

Indicators of Compromise (IoCs):

TypeIndicatorDescription
SHA-256c6b8d0cdb53da98a5d15e79b7bb9e9f4c272c4f9592acdc291089f126f892f45WordPress probing component.
SHA-2560d8ea89a63070f68286249aa437aece0e040c1609b8c5c0950ebbc90e6f70f02Credential-collection component.
SHA-2561e22fde68d3277ed0fe7a8a7b554f0ae118260a2fa143f8e1bdc84c994ebbe90JavaScript secret scanner.
SHA-19903f4576980ff7cfd560ca57c665a4b59b3c30dRelated Go botnet binary with remote command execution capability.
IP Address193.32.162[.]134Additional TIKTOUK control panel.
IP Address195.178.110[.]209Additional TIKTOUK control panel.
IP Address31.56.58[.]59Payload host and controller identified in telemetry.
File Namewp2s_poll.pyPython component for probing WordPress targets.
File Namewp2s_crack.pyPython component focused on credential collection.
File Namejscrawl-amd64Go-based Linux executable scanning JavaScript for secrets.
Targeted Filewp-config.php.bakExposed WordPress configuration backup.
Targeted File.envEnvironment configuration file.
Targeted File Path.git/configRepository configuration file.
REST Request Path/wp/v2/categories/0Targeted route with DELETE operation.
REST Request Path/wp/v2/block-renderer/core/paragraphTargeted route with POST operation.
Reporting Endpoint/v1/ingestEndpoint receiving findings from probing.

Source link: Cybersecuritynews.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Souvik Banerjee

I’m Souvik Banerjee from Kolkata, India. As a Marketing Manager at RS Web Solutions (RSWEBSOLS), I specialize in digital marketing, SEO, programming, web development, and eCommerce strategies. I also write tutorials and tech articles that help professionals better understand web technologies.
Share the Love
Related News Worth Reading