Back to Intelligence

TIKTOUK WordPress Credential Harvesting Toolkit + Microsoft Teams Help Desk Social Engineering: OTX Pulse Analysis — Enterprise Detection Pack

SA
Security Arsenal Team
October 2, 2026
9 min read

Two fresh OTX pulses published on 2026-10-02 reveal a converging threat picture: automated credential harvesting at scale against web infrastructure, and human-led social engineering against enterprise collaboration platforms.

Pulse 1 — TIKTOUK: AlienVault researchers have traced a multi-component credential collection toolkit purpose-built for WordPress environments. TIKTOUK is not a single payload — it is a modular pipeline consisting of three components:

  1. Python probing module — scans internet-facing hosts to identify WordPress installations, fingerprints plugin/theme versions, and probes REST API endpoints for exposed secrets and misconfigurations (associated with CVE-2026-63030, CVE-2026-60137, and CVE-2026-88771).
  2. Python collection module — extracts wp-config.php, database credentials, and SMTP plugin configuration (including encrypted SMTP credentials, which the toolkit decrypts), plus AWS access keys and other secrets stored in configuration files.
  3. Go-based JavaScript crawler — harvests hardcoded secrets, API keys, and tokens from client-side JavaScript served by the target site.

The observed infrastructure at 193.32.162.134 is associated with toolkit operation. The objective is credential aggregation: SMTP relays for spam/phishing infrastructure, AWS keys for cloud pivoting, and database credentials for downstream data theft or site takeover.

Pulse 2 — Microsoft Teams Help Desk Weaponization: A parallel campaign abuses Microsoft Teams external calling to impersonate internal IT help desk staff. Attackers initiate Teams calls to employees, socially engineer them into granting remote access or executing payloads, then move laterally within the network. The domain san-sid.com and a SHA256 payload (24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b) are the extracted indicators.

Collective assessment: While attribution is unknown for both campaigns, they reflect the two dominant initial access patterns of 2026: automated secret scraping against exposed CMS/cloud infrastructure, and identity-centric social engineering bypassing perimeter controls entirely. Organizations running WordPress externally AND using Microsoft Teams with open external federation are exposed to both chains simultaneously.

Threat Actor / Malware Profile

TIKTOUK Toolkit

  • Distribution method: Self-hosted scanning toolkit operated from attacker infrastructure (193.32.162.134). No victim-side delivery required — this is an external reconnaissance-and-collection framework, not a dropped implant.
  • Payload behavior: Python modules perform HTTP(S) probing of WordPress REST API endpoints (/wp-json/), attempt access to backup/exposed config files (wp-config.php.bak, .env, wp-config.php~), and parse SMTP plugin settings. The Go crawler renders pages and recursively scans linked JavaScript bundles for AWS key patterns (AKIA[0-9A-Z]{16}), private keys, and bearer tokens.
  • C2 / exfiltration: Collected credentials are staged back to operator infrastructure; the flagged IPv4 (193.32.162.134) should be treated as the primary collection node.
  • Persistence mechanism: None on the victim host — persistence is achieved by using the stolen credentials (SMTP relay abuse, AWS key reuse, database access) after the scan completes.
  • Anti-analysis: Go-compiled crawler resists casual static analysis; Python components are typically run from VPS infrastructure, leaving minimal victim-side artifacts. The primary forensic trail is in web server access logs, not endpoint telemetry.

Teams Help Desk Impersonation

  • Distribution method: Microsoft Teams external federation. Attackers register lookalike tenants/domains (e.g., san-sid.com) and initiate voice/video calls impersonating IT support, frequently using display names like "Help Desk" or "IT Support."
  • Payload behavior: Victims are coached into launching remote access tooling (Quick Assist, AnyDesk) or executing a staged binary (SHA256 24ab9fe5...c1c5b). Once a foothold exists, the operator performs internal discovery and lateral movement.
  • C2 communication: Standard commercial RMM tooling or beaconing over 443 blended into legitimate traffic.
  • Persistence mechanism: New local accounts, RMM agent registration, and scheduled tasks established during the "support session."
  • Anti-analysis: Heavy reliance on living-off-the-land tooling — Quick Assist (quickassist.exe), signed RMM binaries, and Teams itself — minimizing traditional malware signatures.

IOC Analysis

IndicatorTypeOperationalization
193.32.162.134IPv4Block egress; retro-hunt web server logs for inbound requests from this IP against WordPress paths
CVE-2026-63030 / CVE-2026-60137 / CVE-2026-88771CVEMap against external attack surface inventory; prioritize patching exposed WordPress REST API and plugin flaws
c6b8d0cd...2f45, 0d8ea89a...f02, 1e22fde6...be90 (SHA256); 9903f457...30d (SHA1)File hashesLoad into EDR blocklists; hunt for execution across endpoints and any staging directories
san-sid.comDomainBlock at DNS/proxy; hunt Teams call logs and proxy logs for interactions; treat any user contact from this domain as a suspected social engineering event
24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5bFileHash-SHA256EDR block + retro-hunt; this is the Teams-campaign payload

SOC operationalization guidance: Ingest all indicators into your TI platform via the OTX DirectConnect API or AlienVault USM integration. File hashes go to EDR block rules; the IPv4 goes to firewall egress deny AND inbound WAF alerting (this is scanner infrastructure, so inbound hits in web logs are the high-fidelity signal). The domain should trigger both a DNS block and a proactive review of Teams external access logs. CVE indicators should feed your vulnerability management queue with an externally-facing asset filter.

Detection Engineering

YAML
---
title: TIKTOUK WordPress Credential Collection - Suspicious Config File Access
id: 8f3a2c1e-7b4d-4e9a-b1c6-tikt0uk00001
status: experimental
description: Detects HTTP requests attempting to access exposed WordPress configuration files, environment files, or backup configs consistent with TIKTOUK probing module behavior
author: Security Arsenal Threat Intelligence
references:
    - https://www.levelblue.com/blogs/spiderlabs-blog/tiktouk-tracing-a-wordpress-credential-collection-toolkit
logsource:
    category: webserver
    product: apache
    service: access
detection:
    selection_paths:
        cs-uri|contains:
            - '/wp-config.php'
            - '/wp-config.php.bak'
            - '/wp-config.php~'
            - '/.env'
            - '/wp-json/wp/v2/users'
            - '/wp-content/uploads/.env'
    filter_legit:
        cs-uri|contains: '/wp-config.php'
        cs-method: 'POST'
    condition: selection_paths and not filter_legit
falsepositives:
    - Legitimate site administration (rare for direct config file GET requests)
level: high
tags:
    - attack.discovery
    - attack.t1595
    - attack.t1552
---
title: Suspicious Remote Access Tool Execution Following Teams Activity
id: 9d4b3e2f-8c5e-5f0b-c2d7-t3ams0000002
status: experimental
description: Detects execution of remote access tooling (Quick Assist, AnyDesk, TeamViewer) commonly staged during Microsoft Teams help desk impersonation attacks leading to lateral movement
author: Security Arsenal Threat Intelligence
logsource:
    category: process_creation
    product: windows
detection:
    selection_img:
        Image|endswith:
            - '\quickassist.exe'
            - '\AnyDesk.exe'
            - '\TeamViewer.exe'
            - '\TeamViewerQS.exe'
            - '\ScreenConnect.ClientService.exe'
            - '\dwagent.exe'
    selection_cli:
        CommandLine|contains:
            - 'san-sid.com'
    condition: 1 of selection_*
falsepositives:
    - Legitimate IT support sessions - baseline approved RMM tooling and alert on outliers
level: high
tags:
    - attack.command_and_control
    - attack.t1219
    - attack.t1566
---
title: Scheduled Task Persistence Created During Remote Support Session
id: 1a5c4f3d-9d6f-6a1c-d3e8-p3rs1st00003
status: experimental
description: Detects scheduled task creation by RMM processes or Office/Teams-adjacent processes, a persistence pattern observed in help desk impersonation intrusions
author: Security Arsenal Threat Intelligence
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        Image|endswith: '\schtasks.exe'
        CommandLine|contains: '/create'
    filter_parents:
        ParentImage|endswith:
            - '\sccm.exe'
            - '\msiexec.exe'
    condition: selection and not filter_parents
falsepositives:
    - Software deployment tooling - tune against enterprise software inventory
level: medium
tags:
    - attack.persistence
    - attack.t1053.005
KQL — Microsoft Sentinel / Defender
// Hunt: TIKTOUK scanner infrastructure contact + Teams impersonation payload execution
// Microsoft Sentinel / Defender XDR
let ScannerIP = "193.32.162.134";
let PayloadSHA256 = "24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b";
let SuspiciousDomain = "san-sid.com";
union isfuzzy=true
(DeviceNetworkEvents
 | where RemoteIP == ScannerIP or RemoteUrl has SuspiciousDomain
 | project Timestamp, DeviceName, InitiatingProcessFileName, RemoteIP, RemoteUrl, RemotePort, ActionType),
(DeviceFileEvents
 | where SHA256 == PayloadSHA256
 | project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName),
(DeviceProcessEvents
 | where SHA256 == PayloadSHA256
    or (FileName in~ ("quickassist.exe","AnyDesk.exe","TeamViewer.exe")
        and InitiatingProcessFileName has_any ("Teams.exe","ms-teams.exe","explorer.exe"))
 | project Timestamp, DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, AccountName)
| sort by Timestamp desc
PowerShell
# Security Arsenal - TIKTOUK / Teams Impersonation IOC Hunt Script
# Run as Administrator on endpoints and export results centrally

$Indicators = @{
    ScannerIP     = "193.32.162.134"
    PayloadHash   = "24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b"
    TiktoukHashes = @(
        "c6b8d0cdb53da98a5d15e79b7bb9e9f4c272c4f9592acdc291089f126f892f45",
        "0d8ea89a63070f68286249aa437aece0e040c1609b8c5c0950ebbc90e6f70f02",
        "1e22fde68d3277ed0fe7a8a7b554f0ae118260a2fa143f8e1bdc84c994ebbe90"
    )
    PhishDomain   = "san-sid.com"
}

Write-Output "[*] Checking active and recent network connections to scanner infrastructure..."
Get-NetTCPConnection | Where-Object { $_.RemoteAddress -eq $Indicators.ScannerIP } |
    Select-Object LocalAddress, LocalPort, RemoteAddress, State, OwningProcess |
    ForEach-Object {
        $_ | Add-Member -NotePropertyName ProcessName -NotePropertyValue (Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue).Name
        $_
    }

Write-Output "[*] Checking DNS cache for malicious domain..."
Get-DnsClientCache | Where-Object { $_.Entry -like "*$($Indicators.PhishDomain)*" }

Write-Output "[*] Hunting payload hashes in common staging directories..."
$StagingPaths = @("$env:TEMP", "$env:APPDATA", "$env:LOCALAPPDATA", "C:\Users\Public", "$env:USERPROFILE\Downloads")
foreach ($Path in $StagingPaths) {
    Get-ChildItem -Path $Path -Recurse -File -ErrorAction SilentlyContinue |
        Where-Object { $_.Length -gt 10KB -and $_.Length -lt 200MB } |
        ForEach-Object {
            $Hash = (Get-FileHash $_.FullName -Algorithm SHA256 -ErrorAction SilentlyContinue).Hash
            if ($Hash -eq $Indicators.PayloadHash -or $Indicators.TiktoukHashes -contains $Hash) {
                Write-Output "[ALERT] IOC match: $($_.FullName) ($Hash)"
            }
        }
}

Write-Output "[*] Checking for recently installed RMM tooling (Teams help desk impersonation artifact)..."
$RMMNames = @("AnyDesk","TeamViewer","ScreenConnect","DWAgent","RustDesk","Atera")
Get-ItemProperty HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*,
                HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*,
                HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\* -ErrorAction SilentlyContinue |
    Where-Object { $n = $_.DisplayName; $RMMNames | Where-Object { $n -like "*$_*" } } |
    Select-Object DisplayName, InstallDate, Publisher

Write-Output "[*] Checking scheduled tasks created in the last 7 days..."
Get-ScheduledTask | Where-Object { $_.Date -and ([datetime]$_.Date) -gt (Get-Date).AddDays(-7) } |
    Select-Object TaskName, TaskPath, Date, @{N='Action';E={$_.Actions.Execute}}

Write-Output "[*] Checking for recently created local accounts..."
Get-LocalUser | Where-Object { $_.PasswordLastSet -gt (Get-Date).AddDays(-7) -or $_.LastLogon -gt (Get-Date).AddDays(-7) } |
    Select-Object Name, Enabled, LastLogon, PasswordLastSet

Write-Output "[+] Hunt complete."

Response Priorities

Immediate (0-4 hours):

  • Block 193.32.162.134 at egress firewalls and add inbound alerting on WAF/perimeter for any requests sourced from it — inbound hits against WordPress paths are high-fidelity compromise indicators
  • Push all six file hashes to EDR block policies; block san-sid.com at DNS resolver and proxy layers
  • Search web server access logs for requests to wp-config.php variants, .env files, and /wp-json/ user enumeration endpoints from the last 90 days — TIKTOUK leaves its trail in web logs, not endpoints
  • Query Teams call/chat logs for any external contact from san-sid.com or unknown tenants claiming to be IT support

24 hours:

  • Because TIKTOUK is a credential-stealing operation, assume any WordPress site scanned by this toolkit has had wp-config.php, database credentials, and SMTP plugin secrets harvested — rotate all WordPress database passwords, SMTP relay credentials, and any AWS keys present in site configuration or JavaScript for externally hosted WordPress assets
  • Force credential resets and session revocation for any user who interacted with a suspicious Teams help desk call; verify via out-of-band channel whether legitimate IT contact occurred
  • Audit AWS CloudTrail for anomalous key usage if any AWS credentials were present in scanned web properties

1 week:

  • Restrict Microsoft Teams external access: disable open federation or enforce an allowlist of trusted external domains; enable banner warnings for external callers
  • Harden WordPress deployments: block direct access to wp-config.php and dotfiles at the web server layer, disable unauthenticated REST API user enumeration, move secrets out of config files into a vault, and patch against CVE-2026-63030, CVE-2026-60137, and CVE-2026-88771
  • Deploy application control policy restricting unsigned RMM tooling (AnyDesk, ScreenConnect, RustDesk) to an approved IT-support allowlist — this breaks the Teams impersonation execution chain
  • Roll out user awareness briefing specifically on help desk impersonation: legitimate IT will never cold-call via Teams requesting remote access or credential disclosure

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.