logo

Hackers Exploit React2Shell Vulnerability to Deploy Miners and Botnets Worldwide

ID: d4c85d65-34e8-5685-a3f5-2e8f6bf437ed

STIX ID: report--d4c85d65-34e8-5685-a3f5-2e8f6bf437ed

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2026-01-28

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

React2Shell (CVE-2025-55182) is being actively exploited in the wild to achieve remote code execution in React Server Components via insecure deserialization of Flight protocol data; attackers have leveraged this to deploy a diverse malware ecosystem—XMRig miners, RustoBot and Kaiji DDoS bots, Sliver implants, CrossC2/Cobalt Strike, and EtherRAT—establish persistence (systemd, cron), perform DNS-based exfiltration, and operate C2 infrastructure and domains/IPs across multiple sectors and countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.