dalung is the handle of an operator publicly identified as Saeful Rochim and linked to a large-scale WordPress intrusion operation built around a recovered toolkit known as WP Botnet Master. The operator was assessed as a student of the ISAL Framework, a paid Telegram-based training ecosystem associated with the actor known as KING, rather than the primary instructor or organizer. The operation was tied to dalung through a reported code-authorship fingerprint match and attribution of a recovered botnet server. The activity centered on mass compromise of WordPress sites through a combination of brute-force credential attacks and exploitation of CVE-2025-15001 in the FS Registration Password plugin. The toolkit supported username enumeration, automated password guessing using multiple credential strategies, exploitation-driven administrator account takeover, and subsequent shell deployment. Post-compromise tradecraft included use of the STEALTH FM V65 PHP web shell for persistence, command execution, security-plugin disabling, and anti-forensics. Persistence reportedly extended beyond file-based implants into WordPress database entries, enabling reinfection or continued access after superficial cleanup. The infrastructure was described as a distributed botnet architecture with a master node coordinating more than a dozen Ubuntu-based worker servers. Command and control reportedly used multiple parallel channels, including Telegram and GitHub-hosted configuration or payload delivery, alongside dedicated HTTP endpoints. The tooling included separate components for orchestration, worker execution, standalone brute forcing, and high-concurrency shell redeployment. Victimology indicates broad international targeting across 100 countries, with especially high credential-harvest volumes affecting Brazil, India, and the United Kingdom. Reported affected sectors included government, education, healthcare, and finance. The operation’s primary objective appears to have been large-scale harvesting of WordPress administrator credentials and account takeover, followed by persistent access to compromised websites. Based on the documented behavior, dalung is best characterized as a cybercrime operator involved in credential theft, initial access, persistence, and post-exploitation against internet-facing WordPress environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
22 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.