TIKTOUK: Tracing a WordPress Credential Collection Toolkit

    Date: 10/06/2026

    Severity: High

    Summary

    TIKTOUK, a WordPress credential-collection toolkit comprising Python components and a Go-based Linux crawler that probes websites and extract exposed secrets. The toolkit targets WordPress configuration, backup, environment, and log files, recovering database credentials, AWS keys, API tokens, and encrypted email credentials through configuration-key-based decryption. It also uses SQL injection/REST batch probing and JavaScript secret scanning, with collected data exfiltrated to centralized C2 infrastructure. 

    Indicators of Compromise (IOC) List

    IP Address

    193.32.162.134

    195.178.110.209

    31.56.58.59

    Hash

    0d8ea89a63070f68286249aa437aece0e040c1609b8c5c0950ebbc90e6f70f02

    1e22fde68d3277ed0fe7a8a7b554f0ae118260a2fa143f8e1bdc84c994ebbe90

    c6b8d0cdb53da98a5d15e79b7bb9e9f4c272c4f9592acdc291089f126f892f45

    384c2c944d097271d17d877f30ecff9d4a4e4bd09d743972de8e8c266279178d

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    dstipaddress IN ("193.32.162.134","31.56.58.59","195.178.110.209") or srcipaddress IN ("193.32.162.134","31.56.58.59","195.178.110.209")

    Detection Query 2 :

    sha256hash IN ("0d8ea89a63070f68286249aa437aece0e040c1609b8c5c0950ebbc90e6f70f02","c6b8d0cdb53da98a5d15e79b7bb9e9f4c272c4f9592acdc291089f126f892f45","1e22fde68d3277ed0fe7a8a7b554f0ae118260a2fa143f8e1bdc84c994ebbe90","384c2c944d097271d17d877f30ecff9d4a4e4bd09d743972de8e8c266279178d")

    Reference:    

    https://www.levelblue.com/blogs/spiderlabs-blog/tiktouk-tracing-a-wordpress-credential-collection-toolkit                                                   


    Tags

    MalwareCredential HarvestingWordPressPythonGolangAWSSQL injectionExfiltration

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags