Close Menu
    What's Hot

    Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded

    Opinion | Putin Has No Good Way Out of His War

    Google parent Alphabet to sell $80bn in stock to fund AI plans | Technology News

    Facebook X (Twitter) Instagram
    Trending
    • Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded
    • Opinion | Putin Has No Good Way Out of His War
    • Google parent Alphabet to sell $80bn in stock to fund AI plans | Technology News
    • Whoop Promo Codes May 2026: 20% Off | June 2026
    • Emmanuel Macron’s Versailles glitz masks a fading economic legacy
    • Spygate latest: Southampton boss Tonda Eckert ‘loved’ information gathered when intern spied on opponent, panel’s written reasons reveal | Football News
    • Celtic manager latest: Martin O’Neill and Robbie Keane set for talks | Football News
    • Is the stock market in an AI bubble? A recent warning sign suggests yes
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor

    adminBy adminMay 11, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananMay 11, 2026Vulnerability / Ransomware

    cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor

    A threat actor named Mr_Rot13 has been attributed to the exploitation of a recently disclosed critical cPanel flaw to deploy a backdoor codenamed Filemanager on compromised environments.

    The attack exploits CVE-2026-41940, a vulnerability impacting cPanel and WebHost Manager (WHM) that could result in an authentication bypass and allow remote attackers to gain elevated control of the control panel.

    According to a new report from QiAnXin XLab, the security defect has been exploited by a number of threat actors shortly after its public disclosure late last month, resulting in malicious behaviors like cryptocurrency mining, ransomware, botnet propagation, and backdoor implantation.

    “Monitoring data shows that more than 2,000 attacker source IPs worldwide are currently involved in automated attacks and cybercrime activities targeting this vulnerability,” XLab researchers said. “These IPs are distributed across multiple regions globally, primarily originating from Germany, the United States, Brazil, the Netherlands, and other regions.”

    Cybersecurity

    Further analysis of the ongoing exploitation activity has uncovered a shell script that uses wget or curl to download a Go-based infector from a remote server (“cp.dene.[de[.]com”) that’s designed to implant a compromised cPanel system with an SSH public key for persistent access, along with dropping a PHP web shell that facilitates file upload/download and remote command execution.

    The web shell is then used to inject JavaScript code to serve a customized login page to steal login credentials and siphon them to an attacker-controlled system that’s encoded using the ROT13 cipher (“wrned[.]com”). Once the details are transmitted, the attack chain culminates with the deployment of a cross-platform backdoor that’s capable of infecting Windows, macOS, and Linux systems.

    The infector is also equipped to collect sensitive information from the compromised host, including bash history, SSH data, device information, database passwords, and cPanel virtual aliases (aka valiases), to a 3-member Telegram group created by a user named “0xWR.”

    In the infection sequence analyzed by XLab, Filemanager is delivered via a shell script downloaded from the “wpsock[.]com” domain. The backdoor supports file management, remote command execution, and shell functionality.

    Cybersecurity

    There are signs that the threat actor behind the operation has been operating silently in the shadows for years. This assessment is based on the fact that the command-and-control (C2) domain embedded in the JavaScript code has been put to use in a PHP-based backdoor (“helper.php”) that was uploaded to the VirusTotal platform in April 2022. The domain was first registered in October 2020.

    “Over the six years from 2020 to the present, the detection rate of Mr_Rot13’s related samples and infrastructure across security products has remained extremely low,” XLab said.

    active Backdoor cPanel CVE202641940 deploy Exploitation Filemanager
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticlePODCAST | The Lead: OR Tambo gold bust haunts SAPS major generals. Plus: Cape storm wrap
    Next Article iOS End-To-End Encrypted RCS Messaging Begins Rolling Today In Beta
    admin
    • Website

    Related Posts

    Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded

    June 2, 2026

    Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

    June 1, 2026

    Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts – Krebs on Security

    June 1, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded

    Opinion | Putin Has No Good Way Out of His War

    Google parent Alphabet to sell $80bn in stock to fund AI plans | Technology News

    Whoop Promo Codes May 2026: 20% Off | June 2026

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by