Tradecraft Tuesday Recap: React2Shell, ClickFix, and the Rise of AI Scams
ID: ecd20cca-bf7e-5cef-8f0e-11ed82c8ab2c
STIX ID: report--ecd20cca-bf7e-5cef-8f0e-11ed82c8ab2c
Feed Name: Huntress Blog
Huntress reports rapid, active exploitation of a critical React server RCE (CVE-2025-55182) that has scaled quickly and is delivering cryptominers, a PeerBlight Linux backdoor, tunneling tools and botnet variants; the briefing also highlights social-engineering techniques (ClickFix) that trick users into executing commands, phishing that leverages legitimate services, and scams such as sextortion, romance fraud and pig-butchering, concluding with practical mitigations (MFA/passkeys, password managers, call screening, social media restrictions, credit freezes and treating unexpected inbound messages as suspect).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
