2026-06-06 is live. RBL, certificate, and uptime monitoring — now in public beta.

News

Active Exploitation of cPanel CVE-2026-41940 Used to Install Filemanager Backdoor


Security researchers have linked a series of recent intrusions to a threat actor who goes by the handle Mr_Rot13, alleging the actor has been leveraging a newly disclosed critical vulnerability in cPanel to install a persistent backdoor dubbed “Filemanager” on breached systems.

The exploited issue, tracked as CVE-2026-41940, affects both cPanel and WebHost Manager (WHM). Vulnerable installations are at risk of an authentication bypass that can allow remote attackers to take elevated control of the web hosting control panel.

A report from QiAnXin XLab indicates the flaw was weaponized by multiple malicious groups shortly after its public disclosure late last month. The researchers say the attacks have led to a range of harmful outcomes, including cryptocurrency mining, ransomware deployment, botnet expansion, and the installation of backdoors.

XLab’s telemetry shows the campaign is widespread: in excess of 2,000 attacker source IP addresses are actively engaged in automated exploitation and criminal activity targeting this vulnerability. The hostile traffic originates from many regions, with notable concentrations in Germany, the United States, Brazil and the Netherlands, among others.

Deeper analysis uncovered a shell script used in the intrusion chain that employs either wget or curl to fetch a Go-based infector from a remote server hosted at cp.dene.de.com. That downloader installs an SSH public key to preserve access and writes out a PHP web shell that supports file uploads/downloads and remote command execution.

Operators then abuse the web shell to inject JavaScript that presents a tailored login page designed to harvest credentials. Those stolen credentials are encoded with a ROT13 transformation and exfiltrated to an attacker-controlled domain at wrned.com. The final stage of the chain drops a cross-platform backdoor capable of running on Windows, macOS and Linux hosts.

The Go-based infector also gathers sensitive artefacts from compromised machines-bash history, SSH-related files, system and device details, database credentials and cPanel virtual aliases (valiases)-and forwards the collected data to a three-person Telegram group set up by a user identified as “0xWR.” Researchers observed Filemanager being delivered in the analyzed incidents via a shell script pulled from wpsock.com.

Functionality attributed to the Filemanager implant includes file management, interactive shell access and remote command execution. XLab’s investigation suggests the actor has operated quietly for years: the same C2 domain embedded in the JavaScript was tied to a PHP backdoor named “helper.php” that was uploaded to VirusTotal in April 2022, and the domain registration dates back to October 2020.

Over the period from 2020 until now, detections of artifacts and infrastructure linked to Mr_Rot13 across security products have been consistently low, according to XLab, indicating the campaign has maintained a high degree of stealth.

Indicators to monitor include evidence of wget/curl downloaders, PHP web shells, injected JavaScript that serves fake login pages, ROT13-encoded exfiltration to wrned.com, downloads from cp.dene.de.com and delivery scripts hosted on wpsock.com. Administrators should prioritize patching CVE-2026-41940 and auditing cPanel/WHM access logs for suspicious activity.

First published on May 12, 2026.
Last updated on July 15, 2026.