logo

秘密活动6年的神秘黑客组织Mr_Rot13正在利用cPanel高危漏洞部署后门木马

ID: 0d6eb451-cd51-5875-a442-efe4fdd36d4f

STIX ID: report--0d6eb451-cd51-5875-a442-efe4fdd36d4f

Feed Name: QiAnXin XLab

Threat Score
90/100

Date Published: 2026-05-11

Date Updated: 2026-05-25

Author: Alex.Turing

...
...

This intelligence brief documents active exploitation of CVE-2026-41940 against cPanel/WHM to deploy a Go-based 'Payload' that changes root passwords, implants SSH keys, installs a Python webshell and JS credential-stealer, exfiltrates credentials and system data (including via Telegram), and deploys a cross-platform Filemanager remote access trojan; the activity is attributed to a persistent actor named 'Mr_Rot13' with low-detection infrastructure and global scanning/attack sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.