Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Flaws in JetBrains TeamCity Let Attackers Steal Credentials
October 2, 2026
Critical cPanel & WHM Flaws Let Attackers Run Commands
October 2, 2026
Critical Red Hat Satellite Flaw Lets Attackers Steal Root Passwords, Execute Code
October 2, 2026
Home/Threats/Exposed WordPress Backups Leak AWS and Email Credentials
Threats

Exposed WordPress Backups Leak AWS and Email Credentials

Key Takeaways A sophisticated toolkit named TIKTOUK is actively exploiting exposed WordPress backups to steal AWS and email credentials. The attack chain involves probing WordPress sites, collecting...

David kimber
David kimber
October 2, 2026 5 Min Read
2 0

Key Takeaways

  • A sophisticated toolkit named TIKTOUK is actively exploiting exposed WordPress backups to steal AWS and email credentials.
  • The attack chain involves probing WordPress sites, collecting exposed configuration files, recovering encrypted passwords, and scanning JavaScript for embedded secrets.
  • Researchers discovered a leaked TIKTOUK control panel containing approximately 50,000 server-side credentials from 37,000 domains, including hundreds of validated active AWS keys.
  • The vulnerabilities exploited are associated with CVE-2026-60137 and CVE-2026-63030, affecting WordPress versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2.
  • The incident underscores the critical risk posed by forgotten or publicly accessible backup files, which can lead to widespread credential compromise and cloud environment breaches.

A new, highly effective toolkit dubbed TIKTOUK is leveraging publicly accessible WordPress backups to harvest a trove of sensitive credentials, including those for Amazon Web Services (AWS) and various email platforms. This ongoing operation was already functioning at scale when cybersecurity researchers first identified it.

Table Of Content

  • Key Takeaways
  • TIKTOUK’s Modus Operandi
  • Initial Probing and Exploitation
  • Password Recovery and Detection
  • What You Should Do

Instead of relying on a single exploit, TIKTOUK employs a multi-pronged approach. Its modules systematically scan websites for vulnerable files, recover stored passwords, and extract hidden secrets from JavaScript code delivered to website visitors. The comprehensive nature of this toolkit allows attackers to gather a wide array of valuable authentication data.

Researchers investigating the threat discovered a leaked control panel associated with TIKTOUK, which revealed a staggering collection of approximately 50,000 legitimate server-side credentials spanning roughly 37,000 domains. Crucially, this cache included hundreds of AWS keys that the attackers had already verified as active, indicating a high level of operational success. This discovery was detailed in a report by LevelBlue researchers, who identified the toolkit through extensive source code review, reverse engineering, and controlled testing.

The LevelBlue said in a report that TIKTOUK’s capabilities combine several techniques: probing WordPress installations, collecting exposed configuration files, recovering email passwords, and scanning JavaScript for embedded secrets. These findings underscore the severe implications of unmanaged backup files, which can expose far more than just website databases. Similar incidents involving publicly exposed repository secrets have previously led to the compromise of cloud keys and sensitive business records, illustrating how seemingly minor security oversights can result in extensive data breaches.

TIKTOUK’s Modus Operandi

The TIKTOUK toolkit is composed of two Python modules and a Linux-based crawler developed in Go. Each component operates by retrieving tasks from a central HTTP service and subsequently submitting its findings or status updates. While this service orchestrates task distribution and data collection, researchers did not observe an automated handoff mechanism between the components during their tests.

Initial Probing and Exploitation

The probing component of TIKTOUK initiates its attack by identifying WordPress sites. It then dispatches batch REST requests that cleverly combine a malformed URL with legitimate delete and paragraph-rendering operations. Initially, when these JSON requests encountered “forbidden” responses, the toolkit would automatically switch to multipart encoding, which often resulted in successful responses. This distinct sequence of requests provides a unique forensic signature that defenders can use to detect TIKTOUK activity.

A separate collection component then targets exposed WordPress configuration backups, such as wp-config.php.bak, to extract database credentials and security keys. Beyond backups, it also systematically requests environment settings (e.g., .env), repository configurations (e.g., .git/config), additional database backups (e.g., backup.sql), and debug logs (e.g., wp-content/debug.log). This broad search aims to uncover any credentials or sensitive information that might be inadvertently left accessible through standard web requests.

The collection process further involves nested batch requests designed to retrieve database option values. The component first queries the database to ascertain the options table name, then utilizes this information in subsequent queries to extract specific values. Hexadecimal responses are decoded into plaintext, yielding records that contain critical data such as database settings, email credentials, AWS key pairs, and various API key patterns.

The potential for cloud compromise extends significantly beyond the initial website compromise. The leaked TIKTOUK panel revealed AWS keys that could be exploited for malicious activities like unauthorized email delivery, leveraging computing resources, and accessing AI services. This echoes previous reports where active AWS credentials, once exposed, continued to grant powerful access long after their initial disclosure, highlighting the persistent danger of leaked cloud keys.

Password Recovery and Detection

TIKTOUK’s collector module demonstrates capabilities in decrypting settings from popular WordPress SMTP plugins, including WP Mail SMTP, Easy WP SMTP, and FluentSMTP. Researchers confirmed that the toolkit could recover plaintext credentials by utilizing corresponding encryption keys or other WordPress configuration materials. This functionality doesn’t represent a cryptographic breakthrough but rather an effective method for obtaining the necessary information to unlock protected settings.

Furthermore, controlled experiments showed that decryption could be performed even without optional cryptographic libraries. The collector proved capable of deriving an Amazon SES email password directly from a provided AWS secret, effectively transforming cloud key material into usable credentials for email services.

The JavaScript crawler component of TIKTOUK diligently fetches web pages and their linked scripts, scanning their content for sensitive patterns. It successfully identified patterns associated with services like SendGrid, Anthropic, Bedrock, and AWS. This method of credential harvesting mirrors the Beacon cloud credential breach, where an AWS key exposed within public JavaScript was used to facilitate database theft, illustrating a recurring vulnerability.

While LevelBlue linked the observed request structures to CVE-2026-60137 and CVE-2026-63030, they did not demonstrate successful exploitation in their laboratory environment. Controlled targets provided prepared responses without executing SQL. However, incident telemetry confirmed the successful retrieval of payloads and communication with the command and control server. Investigators also identified a related Go-based botnet with remote command execution capabilities, suggesting a broader, coordinated attack infrastructure.

The advisory for the batch-route vulnerability specifies affected WordPress 6.9.x versions before 6.9.5 and 7.0.x versions before 7.0.2. It’s important to note that the laboratory findings establish the toolkit’s operational behavior but do not independently confirm live-site breaches or the successful exploitation of real WordPress installations in production environments.

What You Should Do

  • Review and Secure Backups: Immediately audit all WordPress backup files to ensure they are not publicly accessible. Move backups to secure, offline storage or cloud storage with strict access controls.
  • Patch WordPress Installations: Update all WordPress installations to the latest versions (6.9.5 or higher for 6.9.x, and 7.0.2 or higher for 7.0.x) to address vulnerabilities CVE-2026-60137 and CVE-2026-63030.
  • Rotate Credentials: Promptly rotate all AWS keys, email credentials (especially for SMTP plugins like WP Mail SMTP, Easy WP SMTP, and FluentSMTP), API keys (SendGrid, Anthropic, Bedrock), and any database credentials.
  • Monitor for Anomalous Activity: Implement robust monitoring for unusual batch requests, changes in HTTP request encoding, and attempts to access sensitive files (e.g., wp-config.php.bak, .env, .git/config, backup.sql, wp-content/debug.log).
  • Scan JavaScript for Secrets: Regularly scan publicly served JavaScript files for hardcoded credentials or API keys that could be exposed.
  • Leverage Indicators of Compromise (IoCs): Integrate the provided IoCs (SHA-256 hashes for toolkit components, IP addresses for control panels, and targeted file paths/REST endpoints) into your security information and event management (SIEM) systems and threat intelligence platforms for detection.
  • Forensic Analysis: If suspicious activity is detected, conduct a thorough forensic analysis, correlating HTTP activity with local records and investigating any payload retrievals or controller communications.

Indicators of Compromise (IoCs):-

Type Indicator Description
SHA-256 c6b8d0cdb53da98a5d15e79b7bb9e9f4c272c4f9592acdc291089f126f892f45 WordPress probing component. <a rel="noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/4a404e3e-2bef-449a-a860-5a75a1244a86/Exposed-WordPress-Backups-Became-a-Gold-Mine-of-AWS-and-Email-Credentials.pdf?AWSAccessKeyId=ASIA2F3EMEYE7HH4HA7T&Signature=UedPuYfQyu21oQDsrplzv%2BC57pI%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEMz%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIFlIoHQ2tuTeUCvW3mE7dYun%2BjwjrF6he1vj4T%2Fshxj7AiEA9ihI5IYG2JMWksZbHOhzVgIG5LrEcrwLhO6Qhrashb4qgwUIlP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDNeIFA8v5LPoOInKFyrXBEysFl2DVRJEq4To5ePfgV%2FgUoObViFPaVhHYYJMOy4qiVEPA43c1wNztQpnQ%2FPpHF2yQLikrfwV8SY51Luzghqxq9bCyf%2FWbLdH1Cw4IsYZ13esQ10Vl3enagSXLAGcqJC1ksk%2B0D%2Bfk8xOulbkrtkQ7JkkkFZGcN9%2F0FHSvVjwT9lxOKGvV%2B11WhYN7LF83XUgL8XDLshBfYDfdkq90Xy4HBmVc7kCsm%2F2cxRMUuK608jJG3QoS7ZT50V1g36ODc1Y2SrRuSKS8Z%2FqCTfPpRgR5JDIOCUOQTRbry6TRuGzRfBYGuBJS%2Fmv3e745%2FWzNvnPvVOR5neKr%2FEvdUZcTpw0Rwg0BRpOf516vfwqD%2FODHB1qc%2B5X9YQKpbyNda2iyBpTX84Fy1WJEOIH0QzWoZFVkacSOIN3Gr3a5B5Ik7c013spBz1DasWuSjP

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCVEExploitSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Critical Zammad Flaws Let Attackers Gain Remote Code Execution

Next Post

OpenClaw Launches Free Open-Source Enterprise Agent Platform for AI Agents

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Zammad Flaws Let Attackers Gain Remote Code Execution
October 2, 2026
Sony PS5 Update Patches Relapse Jailbreak Vulnerabilities
October 2, 2026
Free iCloud Account Vulnerability Allows Email Spoofing
October 2, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us