logo

Malicious NGINX Configurations Enable Large-Scale Web Traffic Hijacking Campaign

ID: 1304123d-fa01-5b47-ba99-14f0ac96f829

STIX ID: report--1304123d-fa01-5b47-ba99-14f0ac96f829

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-02-05

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed an active campaign abusing the critical React2Shell vulnerability (CVE-2025-55182, CVSS 10.0) to inject malicious NGINX configuration blocks (via proxy_pass) and route legitimate web traffic through attacker-controlled backends; the campaign uses a multi-stage shell-script toolkit (zx.sh, bt.sh, 4zdh.sh, zdh.sh, ok.sh) to discover targets (including Baota/BT panels and Asian/.gov/.edu TLDs), maintain persistence, and generate reports of hijacking rules, while telemetry (GreyNoise) shows widespread exploitation from many IPs with concentrated sources deploying cryptominers or reverse shells.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.