React2Shell Exploit Campaigns Tied to North Korean Cyber Intrusion Tactics
ID: 57f09d46-cb58-58be-9c21-13e5624226ab
STIX ID: report--57f09d46-cb58-58be-9c21-13e5624226ab
Feed Name: Infosecurity Magazine (News)
Sysdig observed active campaigns exploiting React2Shell (CVE-2025-55182, CVSS 10.0) that install EtherRAT — a Node.js-based RAT that resolves C2 via Ethereum smart contracts — through a four-stage chain (base64-executed shell, persistent downloader, AES-encrypted JavaScript dropper, and implant). The campaign demonstrates multi-vector persistence, automatic updates, and blockchain-based C2, and shows tooling overlap with North Korean-linked campaigns (Contagious Interview) though attribution remains unconfirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
