React2Shell: 8 months later
ID: 81d99aca-5361-5c7f-a455-5ac191af1f8b
STIX ID: report--81d99aca-5361-5c7f-a455-5ac191af1f8b
Feed Name: Bitbison Blog
Bitbison observed widespread in-the-wild exploitation of the React2Shell RCE over 48 hours, recording 47 compromise events across multiple operator campaigns that delivered miners, credential harvesters and backdoors; DNS exfiltration dominated outbound activity and many operators succeeded within minutes. The report details campaign clusters, identified malware and infrastructure, attacker mistakes, detection comparisons, and actionable defensive advice (dependency resolution, patching, recording request handlers, and treating filenames/hashes as retrospective indicators).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
