PULSE NAME
Mysterious hacker organization operating secretly for 6 years is exploiting critical cPanel vulnerability to deploy backdoor trojans
WHITE Mr_Rot13 AlienVault 2026-05-11 Modified: 2026-05-11
18
IOCs
MEDIUM VOLUME
A previously unknown threat group designated Mr_Rot13 has been exploiting CVE-2026-41940, a critical authentication bypass vulnerability in cPanel & WHM, to compromise Linux servers globally. Active since at least 2020, the group deploys a Go-based payload installer that plants SSH keys, PHP webshells, malicious JavaScript for credential harvesting, and a cross-platform remote access tool called Filemanager. Stolen data is exfiltrated to attacker-controlled Telegram channels and command servers. The group has maintained operational security for six years with extremely low detection rates. Attack infrastructure includes domains registered as early as 2020, with over 2,000 attacking IP addresses observed worldwide. The campaign primarily targets cPanel installations and WordPress systems, with confirmed compromise of Southeast Asian government and military entities resulting in 4.37GB of sensitive data theft.
Indicators of Compromise (18)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2026-41940 2026-05-11
FileHash-MD5 02a5990b11293236e01f174f5999df20 2026-05-11
FileHash-MD5 22613c952459e65ce09fb6b5c1c03d47 2026-05-11
FileHash-MD5 2286f126ab4740ccf2595ad1fa0c615c 2026-05-11
FileHash-MD5 29222f5e73dd10088fcf1204aa21f87f 2026-05-11
FileHash-MD5 2de27ca8d97124adaf604b18161a441e 2026-05-11
FileHash-MD5 45fc93426cf08f91c9f9de5f04a12263 2026-05-11
FileHash-MD5 711afb014f64c97d7b31685709c34ce7 2026-05-11
FileHash-MD5 9305b4ebbb4d39907cf36b62989a6af3 2026-05-11
FileHash-MD5 bae1f1bce7c82fa86f05b12e2e254cfc 2026-05-11
FileHash-MD5 e1ec6ebb96cf87c785ee6a7da677c059 2026-05-11
FileHash-MD5 e49f68a363c867608972680799389daf 2026-05-11
FileHash-MD5 fb1bc3f935fdeb3555465070ba2db33c 2026-05-11
FileHash-SHA1 9ae91b2f03e0b465b18c56abcad3b2b9b7d4e9aa 2026-05-11
FileHash-SHA256 b750c4ac80dcc6e382f3e81fdba843704038a4106d610244d725c8b654e7fde2 2026-05-11
domain wpsock.com 2026-05-11
domain wrned.com 2026-05-11
hostname cp.dene.de 2026-05-11