Hackers Exploit React2Shell Vulnerability to Deploy Miners and Botnets Worldwide
ID: d4c85d65-34e8-5685-a3f5-2e8f6bf437ed
STIX ID: report--d4c85d65-34e8-5685-a3f5-2e8f6bf437ed
Feed Name: The Cyber Express
React2Shell (CVE-2025-55182) is being actively exploited in the wild to achieve remote code execution in React Server Components via insecure deserialization of Flight protocol data; attackers have leveraged this to deploy a diverse malware ecosystem—XMRig miners, RustoBot and Kaiji DDoS bots, Sliver implants, CrossC2/Cobalt Strike, and EtherRAT—establish persistence (systemd, cron), perform DNS-based exfiltration, and operate C2 infrastructure and domains/IPs across multiple sectors and countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
