# TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials from Exposed WordPress Backups and Config Files (CVE-2026-60137, CVE-2026-63030)

> LevelBlue SpiderLabs analyzed TIKTOUK, a toolkit that probes WordPress sites for exposed backup/config files (wp-config.php.bak, .env, .git/config, backup.sql, debug.log) and recovers database, AWS, SMTP and API credentials. A leaked control panel held ~50,000 server-side credentials across ~37,000 domains, including hundreds of actor-validated live AWS keys.

- **Published:** 2026-10-04T00:00:00Z
- **Last reviewed:** 2026-10-04T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2889
- **ID:** TL-2026-2889
- **Severity:** HIGH (CVSS 9.8)
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 23 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-60137, CVE-2026-63030

## Description

TIKTOUK is a three-part credential collection toolkit documented by LevelBlue SpiderLabs (analyst Maor Gabay) on 2026-10-01. The probing component (wp2s_poll.py) fetches target lists and pages to identify WordPress installations, then sends REST batch requests that combine a malformed 'http://' path with DELETE operations against /wp/v2/categories/0 and POST operations against /wp/v2/block-renderer/core/paragraph to fingerprint the site. When a JSON request is rejected (HTTP 403), it retries with multipart encoding, which can flip the response to HTTP 200. It also collects secret-pattern matches from page content alongside target classifications and submits them to the hub.

The credential collection component (wp2s_crack.py) retrieves wp-config.php.bak and parses database credentials and WordPress key/salt material. It sends nested REST batch requests containing author_exclude and UNION ALL SELECT expressions, decodes hexadecimal option values, and queries the options table for plugin settings. It also requests .env, .git/config, backup.sql and wp-content/debug.log. It recovers SMTP passwords from WP Mail SMTP (XSalsa20-Poly1305 secretbox), Easy WP SMTP (AES-256-CTR with a SHA-256-derived key) and FluentSMTP (AES-256-CTR keyed from LOGGED_IN_KEY, with the LOGGED_IN_SALT suffix removed), and derives Amazon SES SMTP passwords from AWS secrets. Results are submitted per target to /api/crack/report on the TIKTOUK panel.

A stripped Linux Go binary, jscrawl-amd64, fetches pages and their referenced JavaScript, scans for secrets (SendGrid, Anthropic, Bedrock tokens, AWS credential pairs) and submits findings to /v1/ingest. A separate Go botnet binary with remote command execution capability is associated with the same infrastructure. Payloads are served from 31.56.58.59, and TIKTOUK control panels were seen on 193.32.162.134 and 195.178.110.209. The whole system runs around a central HTTP hub that distributes tasks and aggregates stolen data.

A leaked panel exposed roughly 50,000 real server-side credentials across ~37,000 domains, including hundreds of actor-validated live AWS keys with SES, EC2 and Bedrock abuse potential. The report links the request structures to the WordPress core 'wp2shell' chain patched on 2026-07-17: CVE-2026-60137 (SQL injection via the author__not_in WP_Query parameter, CWE-89; NVD CVSS 5.9 primary / 9.1 secondary) and CVE-2026-63030 (REST API batch-route confusion at /wp-json/batch/v1, CWE-436, CVSS 9.8), which together enable pre-authentication SQL injection leading to RCE on WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2. Both CVEs were added to the CISA KEV catalog on 2026-07-21 (due dates 2026-07-24 for CVE-2026-63030 and 2026-08-04 for CVE-2026-60137), and a public PoC appeared on GitHub on 2026-07-18; this KEV listing concerns exploitation of the wp2shell chain generally and is not tied to TIKTOUK. LevelBlue's analysis used synthetic target data and an analyst-controlled hub: the link between TIKTOUK and the CVEs rests on request structure only, and exploitation of the CVEs by TIKTOUK against production WordPress was not demonstrated. No threat actor attribution is made.

## MITRE ATT&CK

- T1595.002 Vulnerability Scanning
- T1589.001 Credentials
- T1190 Exploit Public-Facing Application
- T1059.006 Python
- T1140 Deobfuscate/Decode Files or Information
- T1078.004 Cloud Accounts
- T1552.001 Credentials In Files
- T1119 Automated Collection
- T1005 Data from Local System
- T1071.001 Web Protocols

## Sources

- [Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials](https://cybersecuritynews.com/exposed-wordpress-backups/)
- [TIKTOUK: Tracing a WordPress Credential Collection Toolkit (LevelBlue SpiderLabs)](https://www.levelblue.com/blogs/spiderlabs-blog/tiktouk-tracing-a-wordpress-credential-collection-toolkit)
- [WordPress 7.0.2 Security Release](https://wordpress.org/news/2026/07/wordpress-7-0-2-release/)
- [NVD CVE-2026-60137](https://nvd.nist.gov/vuln/detail/CVE-2026-60137)
- [NVD CVE-2026-63030](https://nvd.nist.gov/vuln/detail/CVE-2026-63030)
- [GHSA-fpp7-x2x2-2mjf (CVE-2026-60137)](https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf)
- [GHSA-ff9f-jf42-662q (CVE-2026-63030)](https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q)
- [New wp2shell WordPress Core Flaw Lets Attackers Take Over Sites (The Hacker News)](https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html)
- [CVE-2026-63030 and CVE-2026-60137 (wp2shell): WordPress RCE Explained (Picus Security)](https://picussecurity.com/resource/blog/cve-2026-63030-and-cve-2026-60137-wp2shell-wordpress-rce-explained)
- [CISA Adds Four Known Exploited Vulnerabilities to Catalog (2026-07-21)](https://aviatrix.ai/threat-research-center/cisa-adds-four-known-exploited-vulnerabilities-to-catalog-2026-07-21/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2889
