logo

React2Shell Exploit Campaigns Tied to North Korean Cyber Intrusion Tactics

ID: 57f09d46-cb58-58be-9c21-13e5624226ab

STIX ID: report--57f09d46-cb58-58be-9c21-13e5624226ab

Feed Name: Infosecurity Magazine (News)

Threat Score
90/100

Date Published: 2025-12-09

Date Updated: 2026-04-22

...
...

Sysdig observed active campaigns exploiting React2Shell (CVE-2025-55182, CVSS 10.0) that install EtherRAT — a Node.js-based RAT that resolves C2 via Ethereum smart contracts — through a four-stage chain (base64-executed shell, persistent downloader, AES-encrypted JavaScript dropper, and implant). The campaign demonstrates multi-vector persistence, automatic updates, and blockchain-based C2, and shows tooling overlap with North Korean-linked campaigns (Contagious Interview) though attribution remains unconfirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.