China, Iran are having a field day with React2Shell, Google warns
ID: 5b8a5ee8-b0d0-5520-ab57-59013954db67
STIX ID: report--5b8a5ee8-b0d0-5520-ab57-59013954db67
Feed Name: The Register (Security)
Google and other vendors report widespread, immediate exploitation of a critical React Server Components RCE (CVE-2025-55182, aka React2Shell) by multiple nation-state-linked groups (several China-nexus UNC clusters, North Korea, Iran-linked actors) and criminal operators; attackers have deployed backdoors (Snowlight, Hisonic, Compood, Angryrebel.Linux), tunnelers (Minocat), and XMRig miners across cloud and VPS infrastructure. Additional React vulnerabilities were disclosed, and defenders are advised to patch, monitor outbound wget/cURL activity from web processes, hunt for hidden directories and altered shell configs, and watch the IOCs published by Google.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
