TIKTOUK Toolkit Exploits Exposed WordPress Backups to Harvest Cloud and Email Credentials
Researchers at LevelBlue have uncovered a large-scale cyberattack campaign leveraging a toolkit called TIKTOUK, which systematically exploits exposed WordPress backups to extract sensitive credentials, including cloud and email access keys. The operation, already active at scale when first detected, combines multiple techniques WordPress probing, configuration file collection, password recovery, and JavaScript scanning to harvest high-value secrets.
A leaked control panel revealed that attackers had amassed approximately 50,000 server-side credentials across 37,000 domains, including hundreds of validated AWS keys with potential for abuse in email delivery, computing, and AI services. The toolkit’s modular design includes two Python components and a Go-based Linux crawler, each retrieving tasks from a central HTTP service to coordinate attacks.
How TIKTOUK Operates
- WordPress Probing – The toolkit identifies WordPress sites and sends malformed REST batch requests (e.g., combining
DELETEandPOSToperations) to bypass security controls. When blocked, it retries with multipart encoding, leaving a detectable pattern for defenders. - Credential Collection – A separate component targets exposed backups (e.g.,
wp-config.php.bak,.env,.git/config) to extract database credentials, AWS key pairs, API keys, and SMTP settings. It also decrypts stored email passwords from plugins like WP Mail SMTP and FluentSMTP by leveraging WordPress configuration keys. - JavaScript Scanning – The Go-based crawler fetches web pages and referenced scripts, scanning for secrets tied to SendGrid, Anthropic, Bedrock, and AWS. This mirrors past incidents where exposed AWS keys in public JavaScript led to data breaches.
Impact and Risks
The leaked credentials extend beyond the original compromised site, enabling attackers to abuse cloud resources, send malicious emails, or escalate access. Earlier reports on active AWS keys demonstrate how exposed credentials can retain powerful access long after disclosure.
LevelBlue linked the toolkit’s request structures to CVE-2026-60137 and CVE-2026-63030, though no successful exploitation in live environments was confirmed. Laboratory tests established component behavior, but researchers did not validate stolen credentials from simulated executions.
Detection and Indicators of Compromise (IoCs)
Defenders are advised to monitor for:
- Unusual batch requests with malformed URLs (e.g.,
http://:). - Access to sensitive files (
wp-config.php.bak,.env,debug.log). - Communication with TIKTOUK control panels at 193.32.162[.]134, 195.178.110[.]209, and 31.56.58[.]59.
- Hashes of malicious components:
- WordPress probing:
c6b8d0cdb53da98a5d15e79b7bb9e9f4c272c4f9592acdc291089f126f892f45 - Credential collector:
0d8ea89a63070f68286249aa437aece0e040c1609b8c5c0950ebbc90e6f70f02 - JavaScript scanner:
1e22fde68d83277ed0fe7a8a7b554f0ae118260a2fa143f8e1bdc84c994ebbe90 - Related Go botnet:
9903f4576980ff7cfd560ca57c665a4b59b3c30d
- WordPress probing:
The findings underscore how a single exposed backup can lead to widespread credential theft, with cloud keys and business records becoming accessible through overlooked development materials.
Source: https://cybersecuritynews.com/exposed-wordpress-backups/
AWS for Healthcare & Life Sciences cybersecurity rating report: https://www.rankiteo.com/company/aws-healthcare-lifescience
WordPress cybersecurity rating report: https://www.rankiteo.com/company/wordpress
"id": "AWSWOR1790952139",
"linkid": "aws-healthcare-lifescience, wordpress",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'type': 'Websites'}],
'attack_vector': ['Exposed WordPress backups',
'Malformed REST batch requests',
'JavaScript scanning'],
'data_breach': {'file_types_exposed': ['wp-config.php.bak',
'.env',
'.git/config',
'debug.log'],
'number_of_records_exposed': 'Approximately 50,000',
'personally_identifiable_information': 'Email passwords, AWS '
'keys',
'sensitivity_of_data': 'High (cloud and email access keys, '
'personally identifiable information)',
'type_of_data_compromised': ['Database credentials',
'AWS key pairs',
'API keys',
'SMTP settings',
'Email passwords']},
'description': 'Researchers at LevelBlue uncovered a large-scale cyberattack '
'campaign leveraging a toolkit called TIKTOUK, which '
'systematically exploits exposed WordPress backups to extract '
'sensitive credentials, including cloud and email access keys. '
'The operation combines WordPress probing, configuration file '
'collection, password recovery, and JavaScript scanning to '
'harvest high-value secrets. Attackers amassed approximately '
'50,000 server-side credentials across 37,000 domains, '
'including hundreds of validated AWS keys with potential for '
'abuse in email delivery, computing, and AI services.',
'impact': {'data_compromised': 'Approximately 50,000 server-side credentials',
'operational_impact': 'Potential abuse of cloud resources, '
'malicious email delivery, and escalation of '
'access',
'systems_affected': '37,000 domains'},
'initial_access_broker': {'entry_point': 'Exposed WordPress backups',
'high_value_targets': ['AWS keys',
'Email credentials']},
'lessons_learned': 'A single exposed backup can lead to widespread credential '
'theft, with cloud keys and business records becoming '
'accessible through overlooked development materials.',
'post_incident_analysis': {'corrective_actions': ['Secure backups',
'Monitor for unusual access '
'patterns',
'Enhance credential '
'protection'],
'root_causes': ['Exposed WordPress backups',
'Unsecured configuration files']},
'recommendations': 'Monitor for unusual batch requests, access to sensitive '
'files, and communication with TIKTOUK control panels. '
'Secure WordPress backups and configuration files.',
'references': [{'source': 'LevelBlue'}],
'response': {'enhanced_monitoring': 'Monitoring for unusual batch requests, '
'access to sensitive files, and '
'communication with TIKTOUK control '
'panels',
'third_party_assistance': 'LevelBlue'},
'title': 'TIKTOUK Toolkit Exploits Exposed WordPress Backups to Harvest Cloud '
'and Email Credentials',
'type': 'Credential Harvesting',
'vulnerability_exploited': ['CVE-2026-60137', 'CVE-2026-63030']}