Google Warns Multiple Hacker Groups Are Exploiting React2Shell to Spread Malware
ID: 7f94e6c9-68d1-5ec3-ae76-76b1af105e79
STIX ID: report--7f94e6c9-68d1-5ec3-ae76-76b1af105e79
Feed Name: cybersecurityNews.com
Google Threat Intelligence Group warns of widespread active exploitation of React2Shell (CVE-2025-55182), a critical RSC/Next.js vulnerability (CVSS 10.0) that enables passwordless remote server compromise; multiple actor types — including China-linked espionage groups and opportunistic cybercriminals — are deploying backdoors (HISONIC, COMPOOD, MINOCAT), downloaders (SNOWLIGHT), and miners (XMRig), with exploit code and web-shells publicly circulating and numerous IoCs provided for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
