WordPress backups that are improperly secured have become a target for cybercriminals seeking cloud and email credentials. Leveraging a toolkit named TIKTOUK, attackers are exploiting these vulnerabilities to harvest sensitive information.
Understanding the TIKTOUK Toolkit
The TIKTOUK toolkit stands out due to its multifaceted approach to infiltrating websites. It employs various components that probe for sensitive files, recover stored passwords, and extract secrets from JavaScript loaded by users. Researchers from LevelBlue identified this operation as already widespread when they began their investigation.
Within a leaked control panel, around 50,000 authentic server-side credentials were discovered, spanning approximately 37,000 domains. These credentials included numerous AWS keys which attackers confirmed were still active. Through source code analysis, reverse engineering, and controlled testing, LevelBlue researchers were able to uncover the toolkit’s capabilities.
The Risks of Exposed WordPress Backups
The TIKTOUK operation utilizes two primary Python components and a Linux-based crawler written in Go, which communicate with a central HTTP service. This service manages both the distribution of targets and the collection of information, though tests did not confirm automatic handoff between components.
The initial probing component identifies WordPress sites and issues REST batch requests using malformed URLs. If these requests are denied, the toolkit retries using a different encoding, often resulting in successful data extraction. The subsequent collection component retrieves exposed WordPress backup files, extracting database credentials and security keys.
Impact on Cloud Security
Exposed backup files can reveal more than just a website’s database; they have the potential to expose critical cloud infrastructure. The leaked panel included AWS keys, which could be used for unauthorized email delivery, computing processes, and even AI services. This scenario mirrors previous incidents where exposed AWS credentials enabled unauthorized access long after their initial disclosure.
Moreover, the toolkit’s password recovery capabilities extend to settings encrypted by popular WordPress email plugins. By obtaining the necessary encryption keys, TIKTOUK can convert cloud key material into plaintext credentials, broadening the scope of potential misuse.
Recommendations and Future Outlook
Defenders are advised to monitor for unusual batch requests, changes in request encoding, and access to sensitive files. LevelBlue suggests verifying sample hashes and HTTP activity against local records to confirm incidents. While the laboratory tests did not confirm live-site breaches, they highlight the toolkit’s potential to exploit vulnerabilities in affected WordPress versions.
As the threat landscape evolves, it is crucial for organizations to secure backup files and monitor for signs of compromise. Integrating robust threat intelligence solutions can assist in promptly detecting and responding to such incidents, ultimately safeguarding sensitive credentials from unauthorized access.
