Threat reportMalwareTL-2026-2889

TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials from Exposed WordPress Backups and Config Files (CVE-2026-60137, CVE-2026-63030)

highACTIVE

TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials (TL-2026-2889), also tracked as TIKTOUK, is a high-severity malware campaign scored CVSS 9.8, first published 2026-10-04. It has no confirmed attribution, affects WordPress WordPress core, references 2 CVEs (CVE-2026-60137, CVE-2026-63030), maps to 10 MITRE ATT&CK techniques (T1005, T1059.006, T1071.001), and is covered by 9 detection rules and 23 indicators of compromise.

CVSS
9.8/10High
CVEs
2Referenced vulnerabilities
Techniques
10MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
23Indicators of compromise

Key facts for TL-2026-2889

Threat ID
TL-2026-2889
Also known as
TIKTOUK, wp2shell (associated CVE chain)
Severity
HIGH
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, ecommerce, news - media
Target regions
Global
Detection rules
9
Indicators of compromise
23

Malware and tooling in TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials

Malware and tooling: Go botnet (SHA-1 9903f4576980ff7cfd560ca57c665a4b59b3c30d), TIKTOUK, TIKTOUK HTTP hub

How TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials works

LevelBlue SpiderLabs analyzed TIKTOUK, a toolkit that probes WordPress sites for exposed backup/config files (wp-config.php.bak, .env, .git/config, backup.sql, debug.log) and recovers database, AWS, SMTP and API credentials. A leaked control panel held ~50,000 server-side credentials across ~37,000 domains, including hundreds of actor-validated live AWS keys.

TIKTOUK is a three-part credential collection toolkit documented by LevelBlue SpiderLabs (analyst Maor Gabay) on 2026-10-01. The probing component (wp2s_poll.py) fetches target lists and pages to identify WordPress installations, then sends REST batch requests that combine a malformed 'http://' path with DELETE operations against /wp/v2/categories/0 and POST operations against /wp/v2/block-renderer/core/paragraph to fingerprint the site. When a JSON request is rejected (HTTP 403), it retries with multipart encoding, which can flip the response to HTTP 200. It also collects secret-pattern matches from page content alongside target classifications and submits them to the hub.

The credential collection component (wp2s_crack.py) retrieves wp-config.php.bak and parses database credentials and WordPress key/salt material. It sends nested REST batch requests containing author_exclude and UNION ALL SELECT expressions, decodes hexadecimal option values, and queries the options table for plugin settings. It also requests .env, .git/config, backup.sql and wp-content/debug.log. It recovers SMTP passwords from WP Mail SMTP (XSalsa20-Poly1305 secretbox), Easy WP SMTP (AES-256-CTR with a SHA-256-derived key) and FluentSMTP (AES-256-CTR keyed from LOGGED_IN_KEY, with the LOGGED_IN_SALT suffix removed), and derives Amazon SES SMTP passwords from AWS secrets. Results are submitted per target to /api/crack/report on the TIKTOUK panel.

A stripped Linux Go binary, jscrawl-amd64, fetches pages and their referenced JavaScript, scans for secrets (SendGrid, Anthropic, Bedrock tokens, AWS credential pairs) and submits findings to /v1/ingest. A separate Go botnet binary with remote command execution capability is associated with the same infrastructure. Payloads are served from 31.56.58.59, and TIKTOUK control panels were seen on 193.32.162.134 and 195.178.110.209. The whole system runs around a central HTTP hub that distributes tasks and aggregates stolen data.

A leaked panel exposed roughly 50,000 real server-side credentials across ~37,000 domains, including hundreds of actor-validated live AWS keys with SES, EC2 and Bedrock abuse potential. The report links the request structures to the WordPress core 'wp2shell' chain patched on 2026-07-17: CVE-2026-60137 (SQL injection via the author__not_in WP_Query parameter, CWE-89; NVD CVSS 5.9 primary / 9.1 secondary) and CVE-2026-63030 (REST API batch-route confusion at /wp-json/batch/v1, CWE-436, CVSS 9.8), which together enable pre-authentication SQL injection leading to RCE on WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2. Both CVEs were added to the CISA KEV catalog on 2026-07-21 (due dates 2026-07-24 for CVE-2026-63030 and 2026-08-04 for CVE-2026-60137), and a public PoC appeared on GitHub on 2026-07-18; this KEV listing concerns exploitation of the wp2shell chain generally and is not tied to TIKTOUK. LevelBlue's analysis used synthetic target data and an analyst-controlled hub: the link between TIKTOUK and the CVEs rests on request structure only, and exploitation of the CVEs by TIKTOUK against production WordPress was not demonstrated. No threat actor attribution is made.

MITRE ATT&CK techniques used in TL-2026-2889

Collection

T1005 Data from Local System; T1119 Automated Collection

Execution

T1059.006 Python

Command and Control

T1071.001 Web Protocols

Defense Evasion

T1078.004 Cloud Accounts; T1140 Deobfuscate/Decode Files or Information

Initial Access

T1190 Exploit Public-Facing Application

Credential Access

T1552.001 Credentials In Files

Reconnaissance

T1589.001 Credentials; T1595.002 Vulnerability Scanning

Affected products and versions in TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials

  • WordPress — WordPress core
    Vulnerable versions: 6.8.0-6.8.5 (CVE-2026-60137 only); 6.9.0-6.9.4; 7.0.0-7.0.1
    Fixed in: 6.8.6; 6.9.5; 7.0.2; 7.1 beta2
  • WP Mail SMTP — WP Mail SMTP plugin (stored credentials targeted)
  • Easy WP SMTP — Easy WP SMTP plugin (stored credentials targeted)
  • FluentSMTP — FluentSMTP plugin (stored credentials targeted)

Remediation for TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials

Patches

  • Update WordPress to 6.9.5, 7.0.2 or later (6.8.6 fixes CVE-2026-60137 only)

Immediate actions

  • Remove wp-config.php.bak, .env, .git/, backup.sql and wp-content/debug.log from web-accessible paths
  • Rotate every credential that may have been in exposed files: database, AWS access keys, SMTP/SES, SendGrid and other API keys, and WordPress keys/salts
  • Review AWS CloudTrail for unexpected SES, EC2 and Bedrock activity from rotated keys
  • Block 193.32.162.134, 195.178.110.209 and 31.56.58.59 at the perimeter
  • Search web logs for REST batch requests containing 'http://:' paths, /wp/v2/categories/0 DELETE and block-renderer/core/paragraph POST sub-requests

Workarounds

  • If patching is delayed, block both /wp-json/batch/v1 and rest_route=/batch/v1 at the WAF, and restrict unauthenticated REST access

Longer-term hardening

  • Block dotfile, VCS and backup-extension requests at the web server or WAF
  • Keep secrets out of web roots and out of client-side JavaScript; use a secrets manager
  • Alert on REST batch requests with http:// paths and nested author_exclude/UNION expressions
  • Alert on multipart retries following rejected JSON requests and on sensitive-file access followed by outbound result submissions
  • Disable WP_DEBUG_LOG or write debug logs outside the web root

CVEs associated with TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials

CVE-2026-60137, CVE-2026-63030

Weaknesses (CWE) in TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials

CWE-89, CWE-436

Timeline of TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials

  • WordPress.org enables forced auto-updates for affected versions due to the severity of the chain.
  • NVD publishes CVE-2026-60137 (CWE-89) and CVE-2026-63030 (CWE-436, CVSS 9.8); the RCE chain was reported by Adam Kues of Assetnote/Searchlight Cyber.
  • WordPress releases 7.0.2, 6.9.5 and 6.8.6 fixing the author__not_in SQL injection (CVE-2026-60137) and the REST batch route confusion (CVE-2026-63030); 6.8.6 fixes only the former.
  • Full mechanism of the wp2shell chain is published and a working proof of concept appears on GitHub, making exploitation details public.
  • Rapid7 authenticated vulnerability checks become available for the chain, and Picus publishes a technical breakdown.
  • CISA adds CVE-2026-63030 (due 2026-07-24) and CVE-2026-60137 (due 2026-08-04) to the KEV catalog after widespread active exploitation of the wp2shell chain.
  • LevelBlue SpiderLabs publishes its analysis of the TIKTOUK toolkit (wp2s_poll.py, wp2s_crack.py, jscrawl-amd64) and the ~50k-credential leaked control panel.
  • Cyber Security News reports the findings, listing IOCs and detection guidance.
  • Threadlinqs opens a tracking record for TIKTOUK; LevelBlue notes CVE linkage rests on request structure only and was lab-tested, not shown against production sites.

Sources cited for TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials

Detection coverage for TL-2026-2889

As of 2026-10-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2889 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
23 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats