logo

React2Shell (CVE-2025-55182) actively exploited by threat actors

ID: 8d741831-ceeb-5e24-89df-b2aec424ca99

STIX ID: report--8d741831-ceeb-5e24-89df-b2aec424ca99

Feed Name: Ctrl-Alt-Int3l

Threat Score
80/100

Date Published: 2025-12-08

Date Updated: 2026-04-19

Author: Ctrl-Alt-Int3l

...
...

The report documents widespread, active exploitation of the React2Shell RCE (CVE-2025-55182), attributing activity to multiple actors—including China state‑nexus groups—and detailing observed post‑exploitation deployments such as VShell RAT (and ValleyRAT via DLL sideloading), MeshAgent, XMRig cryptomining scripts, and Mirai-like botnet payloads; it provides technical analysis (payloads, decryption, POC exploit), victimology (Vietnamese and Brazilian targets, government/education), and collated IOCs for detection and hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.