PeerBlight Linux Backdoor Exploits React2Shell CVE-2025-55182
ID: 3f47ac88-edc9-56ba-bb61-c6d19eca4b6f
STIX ID: report--3f47ac88-edc9-56ba-bb61-c6d19eca4b6f
Feed Name: Huntress Blog
Huntress observed active exploitation of the critical React Server Components deserialization RCE (CVE-2025-55182, “React2Shell”) across multiple organizations; attackers used automated scanning to compromise Next.js instances and deployed cryptominers, a resilient BitTorrent-DHT backdoor (PeerBlight), an FRP-based reverse proxy tunnel (CowTunnel), a Go post-exploitation implant (ZinFoq), Kaiji DDoS bot variants, and Sliver droppers — the report includes technical exploit details, malware behavior, persistence/C2 mechanisms, and a large set of IOCs with immediate patching recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
