Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
4 malware familiesExploits CVEs in the wild

Mr_Rot13

Also known asmr_rot13

Mr_Rot13 is a threat actor tracked by QiAnXin XLab and linked to active exploitation of the critical cPanel & WHM authentication bypass vulnerability CVE-2026-41940. The group has been attributed to automated attacks against exposed Linux hosting environments, with researchers reporting more than 2,000 attacker source IPs involved globally. Reported follow-on activity associated with exploitation includes backdoor deployment, credential theft, cryptomining, ransomware, and botnet propagation. In the intrusion chain described in the content, Mr_Rot13 uses a shell script to download a Go-based infector referred to as Payload from infrastructure including cp.dene.de.com. The malware changes the root password, implants an SSH public key for persistence, drops a PHP webshell at /usr/local/cpanel/cgi-sys/cpanel.py, modifies the cPanel login page with malicious JavaScript to steal usernames and passwords, collects bash history, SSH data, device information, database passwords, and valiases data, and exfiltrates data to attacker infrastructure and a Telegram group. The JavaScript hides its credential-theft endpoint using ROT13, decoding to wrned.com. The campaign ultimately installs a cross-platform remote-control trojan/backdoor named Filemanager, delivered via wpsock.com, which supports file management, remote command execution, shell access, and has builds for Linux, Windows, and macOS. XLab states the actor name was derived from the Telegram creator handle "0xWR" and the use of ROT13 obfuscation in the operation. The content also links Mr_Rot13 to older activity involving a PHP backdoor named helper.php that communicated with wrned.com, indicating the group may have operated since at least 2020 and has used stable long-lived infrastructure with low detection rates. The content additionally states that WordPress was also targeted in related activity. Known associated aliases and identifiers mentioned in the content are Mr_Rot13, mr_rot13, and the Telegram handle 0xWR.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Software & Services
MITRE ATT&CK

Tradecraft

35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics48 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1598
Phishing for Information
TA0001
Initial Access
3 techniques
T1078×5
Valid Accounts
T1133
External Remote Services
T1190×4
Exploit Public-Facing Application
TA0002
Execution
2 techniques
T1059×2
Command and Scripting Interpreter
T1059.004×4
Unix Shell
T1059.006
Python
T1059.007
JavaScript
T1574
Hijack Execution Flow
TA0003
Persistence
5 techniques
T1078×5
Valid Accounts
T1098×2
Account Manipulation
T1098.004×6
SSH Authorized Keys
T1133
External Remote Services
T1505×2
Server Software Component
T1505.003×8
Web Shell
T1556×4
Modify Authentication Process
TA0004
Privilege Escalation
3 techniques
T1068×4
Exploitation for Privilege Escalation
T1078×5
Valid Accounts
T1098×2
Account Manipulation
T1098.004×6
SSH Authorized Keys
TA0005
Stealth
5 techniques
T1027×4
Obfuscated Files or Information
T1036×2
Masquerading
T1070
Indicator Removal
T1070.004
File Deletion
T1078×5
Valid Accounts
T1574
Hijack Execution Flow
TA0112
Defense Impairment
1 technique
T1556×4
Modify Authentication Process
TA0006
Credential Access
4 techniques
T1056×5
Input Capture
T1056.003×2
Web Portal Capture
T1056.004
Credential API Hooking
T1555×4
Credentials from Password Stores
T1556×4
Modify Authentication Process
T1649
Steal or Forge Authentication Certificates
TA0007
Discovery
1 technique
T1082
System Information Discovery
TA0009
Collection
3 techniques
T1005×5
Data from Local System
T1056×5
Input Capture
T1056.003×2
Web Portal Capture
T1056.004
Credential API Hooking
T1560
Archive Collected Data
TA0011
Command and Control
4 techniques
T1071×2
Application Layer Protocol
T1071.001
Web Protocols
T1090
Proxy
T1090.003
Multi-hop Proxy
T1105×4
Ingress Tool Transfer
T1219×4
Remote Access Tools
TA0010
Exfiltration
3 techniques
T1041×3
Exfiltration Over C2 Channel
T1048
Exfiltration Over Alternative Protocol
T1567×4
Exfiltration Over Web Service
IOCS

Observables

20 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

secpod blogNews
Jun 3, 2026
CVE-2026-41940 Attacks and Real-World Incidents | SecPod | SecPod

Actively exploiting CVE-2026-41940 to compromise exposed Linux hosting environments using an automated infection chain for persistence, credential theft, and backdoor installation.

Read more
scworldNews
May 12, 2026
Threat actor Mr_Rot13 exploits critical cPanel flaw to deploy Filemanager backdoor | brief | SC Media

Exploiting the cPanel/WebHost Manager authentication bypass vulnerability CVE-2026-41940 to compromise systems, deploy the Filemanager backdoor, establish persistence, steal credentials and sensitive data, and enable follow-on activity including cryptocurrency mining, ransomware deployment, botnet propagation, and cross-platform backdoor installation.

Read more
security affairsNews
May 12, 2026
Attackers exploit cPanel CVE-2026-41940 to deploy Filemanager Backdoor

Long-running threat actor linked to exploitation of CVE-2026-41940 in cPanel to deploy the Go-based Payload malware and the Filemanager backdoor, steal credentials, establish persistence, exfiltrate data, and target WordPress/cPanel environments.

Read more
secpod blogNews
May 12, 2026
Filemanager Fever: MrRot_13’s cPanel Exploitation Campaign Is Spreading Fast - SecPod Blog

Active exploitation of CVE-2026-41940 against cPanel/WHM systems, deploying the Filemanager backdoor, stealing credentials, establishing persistence on Linux hosting environments, and conducting follow-on activity including cryptocurrency mining, ransomware deployment, botnet propagation, and backdoor implantation.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping35

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal4

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs1

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables20

Domains, IPs, and hashes tied to this actor, refreshed continuously.