TIKTOUK Toolkit Exploits Exposed WordPress Backups for AWS and Email Credentials
Attackers are leveraging the TIKTOUK toolkit to harvest AWS and email credentials from exposed WordPress backups, highlighting the persistent risk of forgotten development materials.

A sophisticated toolkit named TIKTOUK is actively exploiting exposed WordPress backups to pilfer sensitive AWS and email credentials, according to recent research. This toolkit employs a multi-pronged approach, combining components for probing WordPress sites, collecting exposed configuration files, recovering email passwords, and scanning JavaScript for embedded secrets. Researchers discovered thousands of domains with exposed credentials, including validated AWS keys, underscoring the significant security risks associated with improperly secured backups and accessible development artifacts.
The TIKTOUK toolkit comprises two Python components and a Go-written Linux crawler, each designed to retrieve tasks from a central HTTP service and report findings. This service orchestrates target distribution and data collection, though the exact handoff mechanism between components remains unclear. The probing component initially identifies WordPress sites and then initiates batch requests using malformed URLs and specific delete/render operations. Defenders can identify this activity by looking for distinctive retry sequences involving multipart encoding in response to forbidden requests.
A dedicated collection component focuses on extracting data from exposed WordPress configuration backups. It targets database credentials, security keys, environment settings, repository configurations, database backups, and debug logs that may be inadvertently left accessible via standard web requests. The component is adept at decoding hexadecimal responses and compiling records that include database settings, email credentials, AWS key pairs, and various API key patterns, effectively turning a single exposed file into a trove of sensitive information.
The implications of these exposed credentials extend far beyond the compromised website itself. A leaked control panel associated with the TIKTOUK operation contained approximately 50,000 server-side credentials across nearly 37,000 domains, including hundreds of validated AWS keys. These keys could grant attackers broad access to cloud services, including email delivery, computing resources, and AI platforms, demonstrating how a seemingly minor oversight can lead to extensive cloud risk.
Further complicating matters, the TIKTOUK collector supports encrypted settings from popular WordPress SMTP plugins like WP Mail SMTP, Easy WP SMTP, and FluentSMTP. It can recover plaintext credentials by leveraging corresponding encryption keys or WordPress configuration data, effectively bypassing encryption without needing specialized cryptographic libraries. The toolkit can even derive Amazon SES email passwords from supplied AWS secret keys, converting cloud access into email service credentials.
In addition to configuration file exploitation, the TIKTOUK toolkit includes a JavaScript crawler that fetches and scans referenced scripts for embedded secrets. Findings from this component have included patterns associated with services like SendGrid, Anthropic, Bedrock, and AWS. This mirrors previous incidents where exposed keys in public JavaScript led to significant data breaches, highlighting the pervasive risk of secrets embedded in client-side code.
While laboratory tests have confirmed the toolkit's capabilities, researchers have not yet demonstrated successful exploitation against live, production WordPress installations. However, the toolkit's components have been linked to CVE-2026-60137 and CVE-2026-63030, and incident telemetry has confirmed payload retrieval and controller communication, alongside the identification of a related Go botnet with remote command execution capabilities. The advisory points to affected WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2.
LevelBlue, the research firm that identified the toolkit, recommends that defenders correlate unusual batch requests, changes in request encoding, sensitive file access, and subsequent result submissions to detect potential compromises. Examining sample hashes alongside HTTP activity and confirming incidents against local records are crucial steps in identifying and mitigating the threat posed by TIKTOUK.