logo

Threat Actor Mr_Rot13 Actively Exploits CVE-2026-41940 for Backdoor Deployment

ID: 9260b807-953b-5ffa-bbbc-3515bbcc4a49

STIX ID: report--9260b807-953b-5ffa-bbbc-3515bbcc4a49

Feed Name: QiAnXin XLab

Threat Score
90/100

Date Published: 2026-05-11

Date Updated: 2026-05-25

Author: Alex.Turing

...
...

### Executive Summary: This report describes active exploitation of a critical unauthenticated cPanel/WHM authentication bypass (CVE-2026-41940, CVSS 9.8) by a persistent actor tracked as "Mr_Rot13". The actor deploys a Go-based infector ("Payload") that implants SSH keys, PHP webshells, malicious JS to harvest credentials (exfiltrated to wrned.com), and installs a cross-platform remote-control backdoor called Filemanager; the campaign has stolen sensitive data (≈4.37 GB) from Southeast Asian government/military targets and leverages Telegram for redundant exfiltration and operational coordination.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.