Full Report
TIKTOUK brings together WordPress probing, collection of exposed configuration data, recovery of encrypted email credentials, and JavaScript secret scanning. Its two Python components and Go-based Linux crawler turn website responses into structured results for a central hub: an HTTP service that distributes target tasks and receives collected data and status reports.
Analysis Summary
# Tool/Technique: TIKTOUK
## Overview
TIKTOUK is a sophisticated modular toolkit designed for large-scale WordPress probing, credential harvesting, and secret scanning. It utilizes a centralized hub-and-spoke model where multiple specialized components retrieve tasks via HTTP and report structured results back to a central C2 server. The toolkit is particularly effective at turning exposed configuration files and encrypted plugin settings into plaintext credentials.
## Technical Details
- **Type:** Attack Framework / Credential Harvester
- **Platform:** Linux (crawler), Multi-platform (Python components), WordPress (Target)
- **Capabilities:** WordPress version probing, REST API exploitation, sensitive file discovery (SQL, env, git), automated decryption of SMTP plugin credentials, and JavaScript secret scanning.
- **First Seen:** Report published October 2026 (LevelBlue/SpiderLabs).
## MITRE ATT&CK Mapping
- **TA0007 - Discovery**
- T1082 - System Information Discovery
- T1595.002 - Active Scanning: Vulnerability Scanning
- **TA0006 - Credential Access**
- T1552.001 - Unsecured Credentials: Private Keys
- T1552.004 - Unsecured Credentials: Contents in Backup Files
- T1606.002 - Forge Web Credentials (focused on plugin settings)
- **TA0010 - Exfiltration**
- T1041 - Exfiltration Over C2 Channel
## Functionality
### Core Capabilities
- **Modular Architecture:** Consists of three primary components:
- `wp2s_poll.py`: Probes for WordPress instances and REST batch routes.
- `wp2s_crack.py`: Extracts database credentials and WordPress keys; performs targeted SQL injections.
- `jscrawl-amd64`: A Go-based crawler that scans JavaScript files for secrets.
- **Exposure Hunting:** Automatically checks for sensitive files including `wp-config.php.bak`, `.env`, `.git/config`, `backup.sql`, and `wp-content/debug.log`.
- **Evasive Probing:** Uses malformed REST batch requests and switches to multipart encoding to bypass security filters that block standard JSON requests.
### Advanced Features
- **Plugin-Specific Decryption:** Contains dedicated routines to decrypt credentials from popular WordPress SMTP plugins by using recovered site keys:
- **WP Mail SMTP:** Decrypts XSalsa20-Poly1305.
- **Easy WP SMTP:** Decrypts AES-256-CTR (SHA-256 derived key).
- **FluentSMTP:** Decrypts AES-256-CTR using `LOGGED_IN_KEY`.
- **Cloud Credential Targeting:** Includes an "AWS mode" specifically designed to extract and report AWS credential pairs.
## Indicators of Compromise
### File Hashes (SHA-256)
- **wp2s_poll.py:** `0d131f6920f01b38f831969d2753a06014e3009d1f32c4f9592acdc291089f126f892f45`
- **wp2s_crack.py:** `0d8ea89a63070f68286249aa437aece0e040c1609b8c5c0950ebbc90e6f70f02`
- **jscrawl-amd64:** `1e22fde68d3277ed0fe7a8a7b554f0ae118260a2fa143f8e1bdc84c994ebbe90`
### Network Indicators
- **C2 Panels:**
- `193.32.162[.]134`
- `195.178.110[.]209`
- **Payload Host:** `31.56.58[.]59`
- **URI Paths:**
- `/api/crack/report` (Data submission)
- `/v1/ingest` (Probing reports)
### Behavioral Indicators
- SQL injection attempts using `UNION ALL SELECT` and `author_exclude` against WordPress REST endpoints.
- Repeated HTTP 403 errors followed by successful multipart/form-data requests to REST batch routes.
## Associated Threat Actors
- Information currently attributed to a broader campaign; specific group names not finalized in the source.
## Detection Methods
- **Behavioral Detection:** Monitor for REST API batch requests containing malformed paths or SQL syntax (e.g., `|||` markers in responses).
- **Log Analysis:** Search for access attempts to `.bak`, `.sql`, and `.git/config` files on web servers.
- **Network Defense:** Identify unusual outbound traffic from web servers to the identified C2 IPs.
## Mitigation Strategies
- **File System Hardening:** Ensure backup files (`.bak`), environment files (`.env`), and `.git` directories are not web-accessible.
- **WordPress Security:** Regularly rotate `LOGGED_IN_KEY` and other salt values in `wp-config.php`.
- **Rate Limiting:** Implement rate limiting and WAF rules for WordPress REST API endpoints, specifically `/wp/v2/batch`.
- **Plugin Maintenance:** Keep all SMTP and security plugins updated to the latest versions.
## Related Tools/Techniques
- **WPScan:** Similar in initial discovery, but TIKTOUK adds automated credential decryption.
- **TruffleHog/GitLeaks:** Similar logic to `jscrawl` for secret scanning, but integrated into an active attack framework.