Today, SOCRadar published new research WP Botnet Master: How a Security Researcher’s Paid Course Built a 2.1-Million-Credential WordPress Botnet.
On 13 July 2026, SOCRadar Researchers recovered the complete toolkit behind a distributed WordPress brute-force operation the operator called “WP Botnet Master.” We expected to be looking at the work of a single skilled attacker. What we found was a graduation project.
The server they pulled apart did not belong to a lone hacker. It belonged to a paying student of a structured, commercial “training” program run by a WordPress security researcher who sells cybercrime as a course – complete with a curriculum, a lab blueprint, a community, and an AI-assisted workflow that lets students build and run credential-harvesting botnets with almost no skill of their own.
One student, acting alone, harvested 2,118,764 WordPress administrator credentials from 606,591 domains across 100 countries. There are roughly 295 more people in the community that trained him. The botnet is a symptom. The academy is the disease.
Key Points:
- A threat actor operating as “KING” (@Real_King_Engine) sells a paid course, the ISAL Framework, that teaches students to stand up attack infrastructure, generate exploits with commercial AI assistants, deploy web shells, and run a credential-harvesting botnet at internet scale.
- KING is a WPScan-credited vulnerability researcher with three published advisories and a Wordfence Intelligence researcher account carrying an approved bounty payout. These are real, verifiable identities – used as legal cover (“educational and defensive research only”) and as a credibility funnel to convert hobbyists into paying students.
- The recovered botnet server does not belong to KING. It belongs to one of his students, a self-published developer who identifies publicly as Saeful Rochim (“dalung,” github.com/dalungid), tied to the recovered toolkit by a confirmed code-authorship fingerprint match.
- The course teaches push-button, AI-assisted exploitation. In a paying student’s own words: “The system did everything automatically – I only drank soda.” Both Anthropic Claude and Google Gemini appear in the toolchain.
- The output SOCRadar recovered: 272 million sites scanned, 2,118,764 administrator credentials harvested across 606,591 domains in 100 countries, and 137 active web shells across 24 countries.
- As of the time of writing, the master command-and-control server (217.216.72.31) remained online and continued ingesting fresh target lists.
This is scalable, repeatable, and deliberately deniable cybercrime. Each of the ~295 community members is a candidate to reproduce the full operation – and an English-language edition of the course is already in development.
To view the full report, please see WP Botnet Master: How a Security Researcher’s Paid Course Built a 2.1-Million-Credential WordPress Botnet
Related
This entry was posted on July 24, 2026 at 9:35 am and is filed under Commentary with tags SOCRadar. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
WP Botnet Master – How a Security Researcher’s Paid Course Built a 2.1-Million-Credential WordPress Botnet
Today, SOCRadar published new research WP Botnet Master: How a Security Researcher’s Paid Course Built a 2.1-Million-Credential WordPress Botnet.
On 13 July 2026, SOCRadar Researchers recovered the complete toolkit behind a distributed WordPress brute-force operation the operator called “WP Botnet Master.” We expected to be looking at the work of a single skilled attacker. What we found was a graduation project.
The server they pulled apart did not belong to a lone hacker. It belonged to a paying student of a structured, commercial “training” program run by a WordPress security researcher who sells cybercrime as a course – complete with a curriculum, a lab blueprint, a community, and an AI-assisted workflow that lets students build and run credential-harvesting botnets with almost no skill of their own.
One student, acting alone, harvested 2,118,764 WordPress administrator credentials from 606,591 domains across 100 countries. There are roughly 295 more people in the community that trained him. The botnet is a symptom. The academy is the disease.
Key Points:
This is scalable, repeatable, and deliberately deniable cybercrime. Each of the ~295 community members is a candidate to reproduce the full operation – and an English-language edition of the course is already in development.
To view the full report, please see WP Botnet Master: How a Security Researcher’s Paid Course Built a 2.1-Million-Credential WordPress Botnet
Share this:
Like this:
Related
This entry was posted on July 24, 2026 at 9:35 am and is filed under Commentary with tags SOCRadar. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.