SecPod

Learn Search

Search across all Learn content

← Back to Security Research
CVE-2026-41940_Mr_Rot13

CVE-2026-41940 - Critical cPanel Vulnerability Exploited in Mr_Rot13 Backdoor campaign

Jun 3, 2026By Santosh Sethuraman

Researchers at QiAnXin XLab have attributed an active exploitation campaign against a critical cPanel authentication bypass vulnerability (CVE-2026-41940) to a long-running threat actor dubbed Mr_Rot13.

The campaign deploys a cross-platform backdoor named Filemanager that steals credentials and establishes persistent access across compromised Linux hosting environments.

More than 2,000 attacker source IPs worldwide have been observed conducting automated attacks against CVE-2026-41940 since its public disclosure on April 28, 2026.

Exploitation activity includes cryptocurrency mining, ransomware deployment, botnet propagation, and backdoor implantation.

ChatGPT Image Jun 2, 2026, 06_05_45 PM.png

Mr_Rot13 & the Filemanager Backdoor

Mr_Rot13 has been operating covertly since at least October 2020, named for their use of the ROT13 cipher to obfuscate C2 addresses and the Telegram handle "0xWR" linked to the group's creator.

Despite six years of continuous activity, their samples and infrastructure maintain near-zero antivirus detections, including a PHP backdoor from 2022 that remains undetected to this day.

Their hallmark is operational discipline: long-lived infrastructure, consistent tooling, and a deliberate preference for stealth over speed.

When an external researcher accidentally interacted with their Telegram bot in May 2026, the group rotated their token within 24 hours.

Their primary payload, Filemanager, is a Go-based cross-platform backdoor with builds for Linux, Windows, and macOS.

It arrives as the final stage of a toolchain that also includes an SSH key implant, a PHP webshell, and a credential-skimming login page, ensuring persistence even if individual components are discovered.

Stolen data is sent simultaneously to an HTTP C2 endpoint and a private Telegram bot, providing a resilient exfiltration channel that survives takedowns. Once running, it exposes a web-based console supporting file management, remote command execution, and shell access.

Attack Methodology: The Automated Infection Chain

Phase 1: Initial Exploitation: CVE-2026-41940 is abused to bypass cPanel/WHM authentication entirely, no credentials needed, full admin access granted remotely.

Phase 2: Infector Delivery: A shell script downloads and runs a Go-based binary ("Update") from the attacker's server via wget/curl, then deletes itself to avoid detection.

Phase 3: SSH Implantation: The infector hardcodes a new root password and plants an attacker-controlled SSH public key, ensuring persistent privileged access.

Phase 4: Webshell Deployment: A PHP webshell ("cpanel.py") is dropped into the cPanel CGI directory, enabling ongoing file access and remote command execution.

Phase 5: Credential Skimming: Malicious JavaScript replaces the cPanel login page, silently harvesting usernames and passwords and sending them to a ROT13-obfuscated C2.

Phase 6: Filemanager Backdoor: A cross-platform backdoor (Windows/Linux/macOS) is installed from wpsock[.]com, opening a web-based remote-control console on a custom TCP port.

Phase 7: Data Exfiltration: Bash history, SSH keys, database passwords, and valiases are sent to the C2 server and a private Telegram group via dual redundant channels.

ChatGPT Image Jun 1, 2026, 06_55_26 PM.pngChatGPT Image Jun 2, 2026, 10_52_00 AM.pngindicators_of_compromise_iocs

Instantly Fix Risks with Saner Patch Management

Saner Patch Management is a continuous, automated, and integrated solution that instantly fixes risks exploited in the wild. It supports major operating systems including Windows, Linux, and macOS, as well as 550+ third-party applications.

It includes a safe testing sandbox to validate patches before production deployment, along with a patch rollback feature in the event of failure or system malfunction, ensuring your infrastructure stays protected without downtime risk.

Featured Posts

Open Critical Atlassian Flaw Exploited Within Hours of Disclosure, Affects Multiple Products
vulnerability researchCritical Atlassian Flaw Exploited Within Hours of Disclosure, Affects Multiple Products

CVE Research

Critical Atlassian Flaw Exploited Within Hours of Disclosure, Affects Multiple Products

Atlassian has disclosed CVE-2026-21589, a critical unauthenticated arbitrary file access flaw affecting Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye Data Center products. Attackers need the exact file path; directory listing is not possible. Cloud is already patched. This article covers impact, fixed versions, and temporary mitigations.

Oct 8, 2026

Open Critical SonicWall SMA 1000 Flaw Lets Unauthenticated Attackers Reach Internal Functionality
vulnerability researchCritical SonicWall SMA 1000 Flaw Lets Unauthenticated Attackers Reach Internal Functionality

CVE Research

Critical SonicWall SMA 1000 Flaw Lets Unauthenticated Attackers Reach Internal Functionality

SonicWall has disclosed CVE-2026-102255, a critical pre-authentication SSRF vulnerability in SMA 1000 Work Place that can let unauthenticated attackers reach internal functionality and perform unauthorized operations. The advisory also covers three additional SMA 1000 issues. Fixed platform-hotfixes are available; SonicWall reports no evidence of in-the-wild exploitation at publication.

Oct 8, 2026

Open New NetScaler SAML Zero-Day Exploited in Targeted Attacks, Causes Denial of Service
vulnerability researchNew NetScaler SAML Zero-Day Exploited in Targeted Attacks, Causes Denial of Service

CVE Research

New NetScaler SAML Zero-Day Exploited in Targeted Attacks, Causes Denial of Service

Citrix has disclosed CVE-2026-88779, a high-severity memory overflow in NetScaler ADC and NetScaler Gateway that can cause denial of service when the appliance is configured as a SAML service provider or identity provider. Targeted attacks on unmitigated deployments have been observed. This article covers impact, affected versions, configuration checks, temporary Global Deny List guidance, and fixed builds.

Oct 8, 2026

Open Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

CVE Research

Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

Oct 5, 2026