logo

Google Warns Multiple Hacker Groups Are Exploiting React2Shell to Spread Malware

ID: 7f94e6c9-68d1-5ec3-ae76-76b1af105e79

STIX ID: report--7f94e6c9-68d1-5ec3-ae76-76b1af105e79

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-12-13

Date Updated: 2026-04-21

Author: Dhivya

...
...

Google Threat Intelligence Group warns of widespread active exploitation of React2Shell (CVE-2025-55182), a critical RSC/Next.js vulnerability (CVSS 10.0) that enables passwordless remote server compromise; multiple actor types — including China-linked espionage groups and opportunistic cybercriminals — are deploying backdoors (HISONIC, COMPOOD, MINOCAT), downloaders (SNOWLIGHT), and miners (XMRig), with exploit code and web-shells publicly circulating and numerous IoCs provided for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.