logo

Critical React2Shell flaw exploited in ransomware attacks

ID: 5df740c6-f543-5759-a0be-9a4518e047ab

STIX ID: report--5df740c6-f543-5759-a0be-9a4518e047ab

Feed Name: Bleeping Computer

Threat Score
76/100

Date Published: 2025-12-17

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers observed attackers exploiting the critical React2Shell (CVE-2025-55182) deserialization flaw to gain unauthenticated RCE and deploy Weaxor ransomware within roughly a minute; the intrusions used obfuscated PowerShell to spawn a Cobalt Strike beacon, disable Defender, encrypt files with a '.WEAX' extension, and remove shadow copies and logs, with no lateral movement observed in the reported case.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.