Cybercriminals Track React2Shell Successes Using Telegram
ID: b80c7e18-864a-5acc-9eb4-e6a3e9c972fd
STIX ID: report--b80c7e18-864a-5acc-9eb4-e6a3e9c972fd
Feed Name: Cyber Press
Threat Score
A large-scale, automated credential-harvesting campaign leveraged the React2Shell RCE (CVE-2025-55182) and a tool called the Bissa scanner to compromise hundreds of internet-facing systems. Operators used AI tooling for automation and debugging, Telegram bots for real-time alerts to an operator, and archived massive quantities of stolen data (including payroll, HR and financial records) to an S3-compatible service (Filebase).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
