Friday, October 2, 2026
Follow on LinkedIn

Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials

Exposed WordPress backups have become a valuable source of cloud and email credentials for attackers using a toolkit called TIKTOUK.

Rather than relying on one technique, its components search websites for sensitive files, recover stored passwords, and collect secrets from JavaScript delivered to visitors. The operation was already active at scale when researchers first observed it.

A leaked control panel contained approximately 50,000 real server-side credentials across about 37,000 domains, including hundreds of AWS keys that the attackers had validated as active. LevelBlue researchers identified the toolkit through source review, reverse engineering, and controlled testing.

LevelBlue said in a report shared with Cyber Security News (CSN) that its components combined WordPress probing, exposed configuration collection, email password recovery, and JavaScript scanning.

The findings highlight how a forgotten backup can expose more than a website database. Similar publicly exposed repository secrets have revealed cloud keys and sensitive business records, showing how accessible development material can widen an otherwise limited security mistake.

Exposed WordPress Backups

TIKTOUK uses two Python components and a Linux crawler written in Go. Each retrieves tasks from a central HTTP service and returns findings or status reports.

The service coordinates target distribution and collection, although the tests did not establish an automatic handoff between components.

The probing component first retrieves targets and identifies WordPress sites. It then sends REST batch requests combining a malformed URL with delete and paragraph-rendering operations.

When JSON requests received forbidden responses, it retried using multipart encoding and received successful responses, giving defenders a distinctive sequence to investigate.

A separate collection component retrieves an exposed WordPress configuration backup and extracts database credentials and security keys.

It also requests environment settings, repository configuration, database backups, and debug logs, looking for credentials left accessible through ordinary web requests.

Nested batch requests contain expressions designed to retrieve database option values. The component first requests the options table name, then uses the returned name in subsequent queries.

It decodes hexadecimal responses into text and prepares records containing database settings, email credentials, AWS key pairs, and API key patterns.

The cloud risk extends beyond the original website. The leaked panel included AWS keys with potential for abuse involving email delivery, computing resources, and AI services.

Earlier reporting on still active AWS credentials likewise showed how exposed keys can retain powerful access long after disclosure.

Password Recovery And Detection

The collector supports encrypted settings from WP Mail SMTP, Easy WP SMTP, and FluentSMTP. Researchers verified that it recovered plaintext credentials using the corresponding encryption keys or WordPress configuration material.

This was not a breakthrough against encryption: the toolkit obtained the information needed to unlock protected settings. Controlled checks also showed that supported decryption worked without optional cryptographic libraries.

The collector could derive an Amazon SES email password from a supplied AWS secret, turning cloud key material into credentials suitable for the email service.

The JavaScript crawler fetches pages and referenced scripts, scans their contents, and sends matches to the hub. Findings included patterns associated with SendGrid, Anthropic, Bedrock, and AWS.

The danger resembles the Beacon cloud credential breach, where an AWS key exposed in public JavaScript enabled database theft.

LevelBlue linked the request structures to CVE-2026-60137 and CVE-2026-63030, but did not demonstrate successful exploitation.

Controlled targets returned prepared responses without executing SQL. Separately, incident telemetry confirmed payload retrieval and controller communication, while investigators identified a related Go botnet with remote command execution capability.

The batch-route advisory identifies affected WordPress 6.9.x versions before 6.9.5 and 7.0.x versions before 7.0.2. Laboratory results establish component behavior, not a confirmed live-site breach.

They do not independently validate stolen credentials collected during simulated executions or demonstrate successful exploitation against a real WordPress installation in production.

Defenders should correlate unusual batch requests, changes in request encoding, sensitive-file access, and subsequent result submissions.

LevelBlue recommends checking sample hashes alongside HTTP activity and confirming incidents against local records. Individual paths or parameters alone do not establish malicious activity.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
SHA-256c6b8d0cdb53da98a5d15e79b7bb9e9f4c272c4f9592acdc291089f126f892f45WordPress probing component.
SHA-2560d8ea89a63070f68286249aa437aece0e040c1609b8c5c0950ebbc90e6f70f02Credential-collection component.
SHA-2561e22fde68d3277ed0fe7a8a7b554f0ae118260a2fa143f8e1bdc84c994ebbe90JavaScript secret scanner.
SHA-19903f4576980ff7cfd560ca57c665a4b59b3c30dRelated Go botnet binary with remote command execution capability.
IP address193.32.162[.]134Additional TIKTOUK control panel.
IP address195.178.110[.]209Additional TIKTOUK control panel.
IP address31.56.58[.]59Payload host and controller observed in incident telemetry.
File namewp2s_poll.pyPython component that probes WordPress targets and reports classifications and secret matches.
File namewp2s_crack.pyPython component that collects configuration data and recovers credentials.
File namejscrawl-amd64Go-based Linux executable that scans referenced JavaScript for secrets.
Targeted filewp-config.php.bakExposed WordPress configuration backup parsed for database credentials and key material.
Targeted file.envEnvironment configuration file requested during sensitive-data collection.
Targeted file path.git/configRepository configuration requested during collection.
Targeted filebackup.sqlDatabase backup requested during collection.
Targeted file pathwp-content/debug.logWordPress debug log requested during collection.
REST request path/wp/v2/categories/0Route targeted with a DELETE operation in batch probes.
REST request path/wp/v2/block-renderer/core/paragraphRoute targeted with a POST operation in batch probes.
Reporting endpoint/v1/ingestReceives findings from the probing component and JavaScript crawler.
Reporting endpoint/api/crack/reportReceives per-target records from the credential collector.
Malformed URL artifacthttp://:Malformed path included in REST batch requests; a contextual detection lead, not a standalone compromise indicator.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Tushar Subhra Dutta
Tushar Subhra Dutta
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Cyber Security Guide

Latest Cyber News

Expert Talks