logo

RST TI Report Digest: 29 Dec 2025

ID: e6042c03-c20d-5993-bbdd-07a5b9ac84a1

STIX ID: report--e6042c03-c20d-5993-bbdd-07a5b9ac84a1

Feed Name: RST Cloud Blog

Threat Score
75/100

Date Published: 2025-12-29

Date Updated: 2026-04-29

Author: RST Cloud

...
...

This report documents active exploitation of CVE-2025-55182 in the React2Shell framework against Russian companies, where attackers deploy XMRig cryptocurrency miners, backdoors (including EtherRAT), Cobalt Strike Unix payloads, Tactical RMM agents, and botnet/flooding tools; the publication provides extensive IOCs (IPs, domains, URLs, and numerous SHA-256 hashes) to support detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.