Mr_Rot13 is a long-running threat actor associated with exploitation of the critical cPanel and WHM authentication-bypass vulnerability CVE-2026-41940 to compromise exposed Linux hosting environments. The actor has been linked to an automated intrusion chain that gains administrative access, implants SSH keys for persistence, deploys a PHP webshell, tampers with cPanel login pages to harvest credentials, exfiltrates sensitive host data, and installs the cross-platform Filemanager backdoor for persistent remote control. Reported collected data includes credentials, SSH-related material, shell history, database passwords, and other administrative information from compromised hosting systems. The actor is named for its use of ROT13-style obfuscation in malicious JavaScript and is also associated with the Telegram handle 0xWR. Activity attributed to this cluster has been assessed as ongoing since at least 2020, with linked tooling and infrastructure indicating operational continuity over multiple years. Researchers have also connected the cluster to earlier PHP backdoor activity targeting WordPress environments, suggesting overlap between hosting-panel compromise and web application backdoor operations. Mr_Rot13’s observed tradecraft includes exploitation of public-facing applications for initial access, credential theft through login-page hijacking, persistence via SSH key implantation and backdoor deployment, remote command execution through webshells and trojans, and exfiltration through both attacker-controlled infrastructure and Telegram. Filemanager, the backdoor deployed in these operations, has been described as a Go-based remote-control trojan with Linux, Windows, and macOS support, enabling file management, shell access, and command execution. Broader exploitation around the same vulnerability has also been associated with cryptomining, ransomware, and botnet propagation, but the high-confidence activity directly tied to Mr_Rot13 centers on credential theft, persistence, remote administration, and data exfiltration from compromised hosting servers.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
20 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Actively exploiting CVE-2026-41940 to compromise exposed Linux hosting environments using an automated infection chain for persistence, credential theft, and backdoor installation.
Exploiting the cPanel/WebHost Manager authentication bypass vulnerability CVE-2026-41940 to compromise systems, deploy the Filemanager backdoor, establish persistence, steal credentials and sensitive data, and enable follow-on activity including cryptocurrency mining, ransomware deployment, botnet propagation, and cross-platform backdoor installation.
Long-running threat actor linked to exploitation of CVE-2026-41940 in cPanel to deploy the Go-based Payload malware and the Filemanager backdoor, steal credentials, establish persistence, exfiltrate data, and target WordPress/cPanel environments.
Active exploitation of CVE-2026-41940 against cPanel/WHM systems, deploying the Filemanager backdoor, stealing credentials, establishing persistence on Linux hosting environments, and conducting follow-on activity including cryptocurrency mining, ransomware deployment, botnet propagation, and backdoor implantation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.