Exposed WordPress backups have become a valuable source of cloud and email credentials for attackers using a toolkit called TIKTOUK.
Rather than relying on one technique, its components search websites for sensitive files, recover stored passwords, and collect secrets from JavaScript delivered to visitors. The operation was already active at scale when researchers first observed it.
A leaked control panel contained approximately 50,000 real server-side credentials across about 37,000 domains, including hundreds of AWS keys that the attackers had validated as active. LevelBlue researchers identified the toolkit through source review, reverse engineering, and controlled testing.
LevelBlue said in a report shared with Cyber Security News (CSN) that its components combined WordPress probing, exposed configuration collection, email password recovery, and JavaScript scanning.
The findings highlight how a forgotten backup can expose more than a website database. Similar publicly exposed repository secrets have revealed cloud keys and sensitive business records, showing how accessible development material can widen an otherwise limited security mistake.
Exposed WordPress Backups
TIKTOUK uses two Python components and a Linux crawler written in Go. Each retrieves tasks from a central HTTP service and returns findings or status reports.
The service coordinates target distribution and collection, although the tests did not establish an automatic handoff between components.
The probing component first retrieves targets and identifies WordPress sites. It then sends REST batch requests combining a malformed URL with delete and paragraph-rendering operations.
When JSON requests received forbidden responses, it retried using multipart encoding and received successful responses, giving defenders a distinctive sequence to investigate.
A separate collection component retrieves an exposed WordPress configuration backup and extracts database credentials and security keys.
It also requests environment settings, repository configuration, database backups, and debug logs, looking for credentials left accessible through ordinary web requests.
Nested batch requests contain expressions designed to retrieve database option values. The component first requests the options table name, then uses the returned name in subsequent queries.
It decodes hexadecimal responses into text and prepares records containing database settings, email credentials, AWS key pairs, and API key patterns.
The cloud risk extends beyond the original website. The leaked panel included AWS keys with potential for abuse involving email delivery, computing resources, and AI services.
Earlier reporting on still active AWS credentials likewise showed how exposed keys can retain powerful access long after disclosure.
Password Recovery And Detection
The collector supports encrypted settings from WP Mail SMTP, Easy WP SMTP, and FluentSMTP. Researchers verified that it recovered plaintext credentials using the corresponding encryption keys or WordPress configuration material.
This was not a breakthrough against encryption: the toolkit obtained the information needed to unlock protected settings. Controlled checks also showed that supported decryption worked without optional cryptographic libraries.
The collector could derive an Amazon SES email password from a supplied AWS secret, turning cloud key material into credentials suitable for the email service.
The JavaScript crawler fetches pages and referenced scripts, scans their contents, and sends matches to the hub. Findings included patterns associated with SendGrid, Anthropic, Bedrock, and AWS.
The danger resembles the Beacon cloud credential breach, where an AWS key exposed in public JavaScript enabled database theft.
LevelBlue linked the request structures to CVE-2026-60137 and CVE-2026-63030, but did not demonstrate successful exploitation.
Controlled targets returned prepared responses without executing SQL. Separately, incident telemetry confirmed payload retrieval and controller communication, while investigators identified a related Go botnet with remote command execution capability.
The batch-route advisory identifies affected WordPress 6.9.x versions before 6.9.5 and 7.0.x versions before 7.0.2. Laboratory results establish component behavior, not a confirmed live-site breach.
They do not independently validate stolen credentials collected during simulated executions or demonstrate successful exploitation against a real WordPress installation in production.
Defenders should correlate unusual batch requests, changes in request encoding, sensitive-file access, and subsequent result submissions.
LevelBlue recommends checking sample hashes alongside HTTP activity and confirming incidents against local records. Individual paths or parameters alone do not establish malicious activity.
Indicators of compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
