cliproot is a seller handle observed advertising a toolkit called Kurosaki for WordPress-focused intrusion activity. The advertised package was described as including tooling for exploitation, credential checking, shell hunting, and Telegram-based operation, indicating support for automated compromise workflows against WordPress environments. A direct operational relationship between cliproot and the ISAL Framework ecosystem or the actor known as KING has not been confirmed. Available reporting supports only limited attribution and behavioral assessment for cliproot. The actor appears associated with the sale or promotion of offensive tooling rather than a fully documented intrusion set. Based on the advertised functionality, the toolkit is consistent with capabilities used in WordPress account takeover and post-compromise shell management, including brute-force or credential validation activity, exploitation support, and web-shell discovery or handling. High-confidence evidence tying cliproot to specific victim countries, sectors, ransomware operations, or a nation-state sponsor is not currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.