logo

North Korean Hackers Exploit React2Shell Vulnerability in the Wild to Deploy EtherRAT

ID: ad68a8e0-622e-5022-911d-d1c93a29b65b

STIX ID: report--ad68a8e0-622e-5022-911d-d1c93a29b65b

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-12-10

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Sysdig Threat Research discovered EtherRAT, a highly sophisticated DPRK-linked malware implant exploiting the critical React2Shell vulnerability (CVE-2025-55182) in React Server Components and Next.js; EtherRAT uses an Ethereum smart-contract-based ‘consensus’ C2 (querying multiple public RPC endpoints), disguises C2 polling as static asset requests, downloads a legitimate Node.js runtime, and implements multiple persistence mechanisms. The report includes IOCs (staging IP 193.24.123.68:3001, smart contract 0x22f96d61cf118efabc7c5bf3384734fad2f6ead4, RPC endpoints, file/process artifacts) and urges immediate patching to React/Next.js 19.2.1+ and hunting for anomalous RPC traffic and runtime persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.