Malicious NGINX Configurations Enable Large-Scale Web Traffic Hijacking Campaign
ID: 1304123d-fa01-5b47-ba99-14f0ac96f829
STIX ID: report--1304123d-fa01-5b47-ba99-14f0ac96f829
Feed Name: The Hacker News
Researchers disclosed an active campaign abusing the critical React2Shell vulnerability (CVE-2025-55182, CVSS 10.0) to inject malicious NGINX configuration blocks (via proxy_pass) and route legitimate web traffic through attacker-controlled backends; the campaign uses a multi-stage shell-script toolkit (zx.sh, bt.sh, 4zdh.sh, zdh.sh, ok.sh) to discover targets (including Baota/BT panels and Asian/.gov/.edu TLDs), maintain persistence, and generate reports of hijacking rules, while telemetry (GreyNoise) shows widespread exploitation from many IPs with concentrated sources deploying cryptominers or reverse shells.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
