Mr_Rot13
- First seen
- 2020-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- team
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:27:03
Targeted industries: technology-and-telecommunications media-and-entertainment
Context
Mr_Rot13 is a stable hacking group identified through a PHP backdoor and a Downloader domain linked to a C2 infrastructure active since 2020. They utilize the Rot13 algorithm for obfuscation and have demonstrated a low detection rate across security products, indicating advanced operational security. Their activities include exploiting CVE-2026-41940 to deliver malicious payloads and maintaining covert communication via Telegram. The group has shown a particular focus on WordPress as a target, with ongoing operations that suggest a sophisticated threat actor rather than opportunistic attackers.
Exploited vulnerabilities
- CVE-2026-41940 (vulnerability)
Reports & references
- blog.xlab.qianxin.com — Mr Rot13 The Elusive 6 Year Hacker Group Weaponizing Critical Cpanel Flaws For Backdoor Deployment (report)