logo

Multiple Threat Actors Rapidly Exploit React2Shell: A Case Study of Active Compromise

ID: 1beb6559-794c-5ce9-b5e7-bbf74a7b8eca

STIX ID: report--1beb6559-794c-5ce9-b5e7-bbf74a7b8eca

Feed Name: JPCERT Blog

Threat Score
78/100

Date Published: 2026-02-13

Date Updated: 2026-04-19

Author: 喜野 孝太(Kota Kino)

...
...

This JPCERT/CC case study describes rapid, widespread exploitation of CVE-2025-55182 (React2Shell) beginning within days of disclosure: multiple threat actors used automated probes to compromise servers, deploy coin miners (xmrig), install backdoors (HISONIC), SNOWLIGHT downloader, and CrossC2, abuse Global Socket for remote access, and conduct website defacements; the report provides an attack timeline, malware hashes, C2 IPs, and recommends prompt patching and detection of compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.