logo

Cybercriminals Track React2Shell Successes Using Telegram

ID: b80c7e18-864a-5acc-9eb4-e6a3e9c972fd

STIX ID: report--b80c7e18-864a-5acc-9eb4-e6a3e9c972fd

Feed Name: Cyber Press

Threat Score
88/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Varshini

...
...

A large-scale, automated credential-harvesting campaign leveraged the React2Shell RCE (CVE-2025-55182) and a tool called the Bissa scanner to compromise hundreds of internet-facing systems. Operators used AI tooling for automation and debugging, Telegram bots for real-time alerts to an operator, and archived massive quantities of stolen data (including payroll, HR and financial records) to an S3-compatible service (Filebase).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.