LevelBlue researchers identified TIKTOUK, a credential-harvesting toolkit that probes WordPress sites for publicly exposed backups, configuration files, and other sensitive material. Its Python components fingerprint targets, send distinctive REST batch requests, retrieve exposed data, and extract credentials from supported SMTP plugins, while a Go crawler searches public JavaScript for embedded secrets. The toolkit targets database, email, cloud, and API credentials and sends collected results to centralized HTTP endpoints.
A leaked TIKTOUK control panel reportedly contained about 50,000 server-side credentials from roughly 37,000 domains, including hundreds of AWS keys said to have been validated as active. Researchers linked elements of its request structure to CVE-2026-60137 and CVE-2026-63030, but did not demonstrate exploitation or SQL execution against a live production WordPress site. Telemetry confirmed payload retrieval and controller communications, and investigators also identified a related Go botnet with remote-command-execution capability; organizations should remove publicly reachable backup and configuration files and rotate potentially exposed credentials.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Incident telemetry confirmed payload retrieval and communications with TIKTOUK controller infrastructure, including 31.56.58[.]59. Investigators also identified a related Go botnet binary with remote command-execution capability.
Researchers linked elements of TIKTOUK's REST batch request structure to CVE-2026-60137 and CVE-2026-63030. They did not demonstrate successful exploitation of either vulnerability or SQL execution against a live production WordPress site.
LevelBlue identified TIKTOUK as a toolkit that probes WordPress sites for exposed backups, configuration files, logs, database dumps, and JavaScript secrets, then collects database, email, cloud, and API credentials. Its components include Python probing and credential-collection tools and a Go-based JavaScript crawler that report to centralized HTTP infrastructure.
Investigators found a leaked TIKTOUK control panel containing approximately 50,000 server-side credentials associated with roughly 37,000 domains. The panel included hundreds of AWS access keys that operators reportedly had validated as active.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourcelevelblue.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.