RST TI Report Digest: 29 Dec 2025
ID: e6042c03-c20d-5993-bbdd-07a5b9ac84a1
STIX ID: report--e6042c03-c20d-5993-bbdd-07a5b9ac84a1
Feed Name: RST Cloud Blog
Threat Score
This report documents active exploitation of CVE-2025-55182 in the React2Shell framework against Russian companies, where attackers deploy XMRig cryptocurrency miners, backdoors (including EtherRAT), Cobalt Strike Unix payloads, Tactical RMM agents, and botnet/flooding tools; the publication provides extensive IOCs (IPs, domains, URLs, and numerous SHA-256 hashes) to support detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
