logo

China, Iran are having a field day with React2Shell, Google warns

ID: 5b8a5ee8-b0d0-5520-ab57-59013954db67

STIX ID: report--5b8a5ee8-b0d0-5520-ab57-59013954db67

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-12-15

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Google and other vendors report widespread, immediate exploitation of a critical React Server Components RCE (CVE-2025-55182, aka React2Shell) by multiple nation-state-linked groups (several China-nexus UNC clusters, North Korea, Iran-linked actors) and criminal operators; attackers have deployed backdoors (Snowlight, Hisonic, Compood, Angryrebel.Linux), tunnelers (Minocat), and XMRig miners across cloud and VPS infrastructure. Additional React vulnerabilities were disclosed, and defenders are advised to patch, monitor outbound wget/cURL activity from web processes, hunt for hidden directories and altered shell configs, and watch the IOCs published by Google.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.