logo

Distribution of EtherRAT Malware Exploiting React2Shell Vulnerability (CVE-2025-55182)

ID: 79ec4102-ef0c-5606-941a-f9fae75dfbb6

STIX ID: report--79ec4102-ef0c-5606-941a-f9fae75dfbb6

Feed Name: ASEC

Threat Score
75/100

Date Published: 2025-12-11

Date Updated: 2026-04-26

Author: ATCP

...
...

AhnLab ASEC discovered an active campaign exploiting the React2Shell vulnerability to install a Node.js-based multi-stage payload that ultimately deploys EtherRAT. The attacker uses automated scanning of random IPs and sends crafted POST payloads to vulnerable React servers; the dropped installer fetches Node.js, decrypts an embedded payload, and runs EtherRAT which retrieves its C2 from an Ethereum smart contract. The malware performs cryptocurrency wallet and SSH key theft, registers SSH keys for persistence, redirects infected hosts, excludes former Soviet countries by locale, and periodically contacts C2 servers (e.g., 91.215.85.42:3000). The report includes IOCs (URLs, IPs, MD5s, SSH key text), code excerpts, and response guidance such as checking for unexpected Node.js installs and Ethereum contract query access logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.