A threat actor, named Mr_Rot13, has been linked to exploiting a recently disclosed critical vulnerability in cPanel, with the aim of deploying the Filemanager backdoor in compromised environments.

cPanel vulnerability exploit
The attack exploits the CVE-2026-41940, which affects cPanel and WebHost Manager (WHM) and can lead to authentication bypass, allowing remote attackers to gain elevated control over the control panel.
According to a new report from QiAnXin XLab, the vulnerability has been exploited by multiple threat actors since its public disclosure late last month. Researchers have identified malicious behaviors such as cryptocurrency mining, ransomware, botnet propagation, and backdoor implantation.
See also: Apple fixes serious security vulnerabilities
“Monitoring data shows that more than 2,000 source IPs of attackers worldwide are currently involved in automated attacks and cybercrime activities targeting this vulnerability,” XLab researchers said. “These IPs are distributed across multiple regions globally, primarily originating from Germany, the United States, Brazil, the Netherlands, and other regions.”
Further analysis of the malicious activity has revealed a shell script that uses wget or curl to download an infector (based on the Go language) from a remote server (“cp.dene.[de[.]com”). This is “implanted” into a compromised cPanel system with a public SSH key for persistent access, while also installing a PHP web shell that facilitates file uploads/downloads and remote command execution.

The web shell is then used to inject JavaScript code to display a custom login page to steal credentials and send them to a system controlled by the attacker. Once the credentials are transmitted, the attack chain is completed by deploying a cross-platform backdoor, capable of infecting Windows, macOS, and Linux.
See also: Google discovered zero-day attacks created with the help of AI
The infector is also equipped to collect sensitive information from the compromised computer, including bash history, SSH data, device information, database passwords, and cPanel virtual aliases (also known as valiases).
File manager backdoor
In the infection sequence analyzed by XLab, Filemanager is delivered via a shell script downloaded from the domain “wpsock[.]com.” The backdoor supports file management, remote command execution, and shell functionality.
There are indications that the threat actor has been operating “silently” for years. This assessment is based on the fact that the command-and-control (C2) domain embedded in the JavaScript code has been used in a PHP-based backdoor (“helper.php”) that was uploaded to the VirusTotal platform in April 2022. The domain was first registered in October 2020.
“Over the six years from 2020 to the present, the detection rate of Mr_Rot13 related samples and infrastructure in security products has remained extremely low,” XLab reported.
See also: Dirty Frag vulnerability in Linux provides root access

This case highlights once again how quickly cybercriminals exploit new vulnerabilities soon after they are made public. The activity of the threat actor Mr_Rot13 and the use of the Filemanager backdoor demonstrate that even popular server management platforms, such as cPanel, can become entry points for large-scale attacks when security updates are delayed. Attackers primarily target poorly protected systems, gaining access to files, databases, and critical website and hosting management functions.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Cybersecurity experts warn that organizations and infrastructure managers should adopt a more aggressive strategy for updating and monitoring systems. Prompt patching, multi-factor authentication, and continuous detection of suspicious activity are now considered essential measures against modern threats. In an era where exploits are released within hours of a vulnerability being disclosed, speed of response is a key factor in preventing serious data breaches and ransomware attacks.
