logo

React2Shell Side Quest: Tracking Down Malicious MeshCentral Nodes

ID: aae73e66-03fe-557b-82b7-52cfbce40036

STIX ID: report--aae73e66-03fe-557b-82b7-52cfbce40036

Feed Name: GreyNoise Labs

Threat Score
75/100

Date Published: 2025-12-09

Date Updated: 2026-04-27

Author: hrbrmstr

...
...

A campaign using React2Shell RCE exploits (CVE-2025-55182 and CVE-2025-66478) was observed downloading and installing MeshCentral RMM agents from a recently-registered domain (aupporte.com) to achieve persistent, remote control. The report analyzes the malicious command and meshinstall.sh installer (including SHA256), enumerates hosting and geolocation inconsistencies, lists dozens of observed MeshCentral-related IPs, and offers detection and mitigation guidance such as baselining RMM usage, monitoring agent install behaviors, and implementing application allowlisting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.