Guide

Exposed WordPress Backups Let TIKTOUK Toolkit Derive AWS SES Passwords and Steal Mail Credentials

The files website owners forget about are becoming the easiest way into their infrastructure. LevelBlue SpiderLabs researcher Maor Gabay has traced a crede

The files website owners forget about are becoming the easiest way into their infrastructure. LevelBlue SpiderLabs researcher Maor Gabay has traced a credential-collection toolkit called TIKTOUK that sweeps WordPress sites for exposed leftovers and turns them into working access to email and cloud accounts.

TIKTOUK is not built around a clever new exploit. It is a set of Python scripts plus a Go crawler for Linux that pulls target lists from a central hub, checks sites at scale and reports whatever it finds back to its operators. What it hunts for is mundane: configuration backups, environment files, git configuration, SQL dumps and debug logs that were left reachable on the public web.

Those leftovers are worth far more than they look. From a leaked WordPress configuration, the toolkit can recover the encrypted settings stored by popular mail plugins, namely WP Mail SMTP, Easy WP SMTP and FluentSMTP, GBHackers reports. When an AWS secret access key turns up in the same pile, TIKTOUK can derive the matching Amazon SES SMTP password, handing attackers a trusted, reputation-rich channel for sending mail as the victim.

The scale is the alarming part. A control panel tied to the operation reportedly held about 50,000 real server-side credentials spread across roughly 37,000 domains, including hundreds of AWS keys the actors had already validated as live, according to Cyber Security News. That is less a hacking campaign than a standing inventory of other people's infrastructure, ready to be used or sold.

Researchers also saw the toolkit probing for known WordPress vulnerabilities, though they did not show it achieving remote code execution. Keeping WordPress current matters, but the bigger lesson is hygiene: a stray backup file can leak more than any unpatched plugin.

Stolen mail credentials feed the same machine that powers modern phishing, from kits like Milk Dragon relaying bank OTPs in real time to lures such as the CloudSyncd fake Zoom campaign hiding behind Unicode tricks on macOS. Mail that comes from a real, authenticated sender is exactly what those operations need to slip past filters.

For site owners, the uncomfortable takeaway is that the breach may already have happened without a single line of code being exploited. Anything sitting in a public web directory should be assumed to be read, and any key stored there should be rotated.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free