Threat Actor Mr_Rot13 Actively Exploits CVE-2026-41940 for Backdoor Deployment
ID: 9260b807-953b-5ffa-bbbc-3515bbcc4a49
STIX ID: report--9260b807-953b-5ffa-bbbc-3515bbcc4a49
Feed Name: QiAnXin XLab
### Executive Summary: This report describes active exploitation of a critical unauthenticated cPanel/WHM authentication bypass (CVE-2026-41940, CVSS 9.8) by a persistent actor tracked as "Mr_Rot13". The actor deploys a Go-based infector ("Payload") that implants SSH keys, PHP webshells, malicious JS to harvest credentials (exfiltrated to wrned.com), and installs a cross-platform remote-control backdoor called Filemanager; the campaign has stolen sensitive data (≈4.37 GB) from Southeast Asian government/military targets and leverages Telegram for redundant exfiltration and operational coordination.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
