logo

React2Shell to real-world breach: How an unpatched dev server led to a Windows compromise

ID: 8f2f02ea-c113-5100-b67f-cf5805905777

STIX ID: report--8f2f02ea-c113-5100-b67f-cf5805905777

Feed Name: ThreatLocker Blog

Threat Score
80/100

Date Published: 2025-12-29

Date Updated: 2026-05-01

...
...

React2Shell (CVE-2025-55182) is a critical (CVSS 10.0) RCE in React server components allowing unauthenticated command execution via crafted HTTP POST requests; in observed incidents attackers exploited unpatched IIS development servers to attempt cryptojacking with xmrig, used Linux-to-Windows pivoting, attempted persistence via AnyDesk and PowerShell shells, and employed evasion techniques. The report includes IOCs (hashes, IPs, domains, commands), analysis of deployment/evasion scripts, and remediation recommendations such as immediate patching, application allowlisting, and least-privilege service accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.