INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

React2Shell Exploit Found

| 2026-02-20 21:07 HIGH HIGH
Executive Summary AI-generated
A threat actor is reportedly targeting major industries worldwide, particularly in the US government and defense sectors. The group behind this reconnaissance effort has been linked to state-sponsored actors from Iran and North Korea. Researchers have identified a cyber espionage campaign using opportunistic exploitation of Linux-specific payloads against Windows endpoints, suggesting that attackers may be seeking big game targets such as financial institutions and industrial organizations. This early stage of reconnaissance precedes actual attacks, highlighting the potential for future malicious activities.
Technical Mitigations AI-generated
* Implement robust patching and vulnerability scanning: Ensure that all systems, networks, and applications receive timely patches for React2Shell to prevent exploitation. Regularly scan for vulnerabilities using automated tools like Nessus or OpenVAS. * Use secure coding practices: Implement secure coding guidelines in development teams to reduce the likelihood of introducing new vulnerabilities into codebases. This includes following best practices for input validation, error handling, and memory management. * Monitor network traffic and system logs: Continuously monitor network traffic and system logs for suspicious activity that may indicate React2Shell exploitation. Use tools like Wireshark or ELK Stack to analyze log data. * Implement rate limiting and IP blocking: Implement rate limiting on public-facing services and block known IP addresses suspected of being involved in React2Shell attacks. This can help prevent the spread of malware and reduce the effectiveness of botnets. * Use secure communication protocols: Ensure that all communication between systems, networks, or applications uses secure protocols like TLS/SSL to protect data in transit. Avoid using insecure protocols like HTTP/1.0 or FTP for sensitive information.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-66478CVE-2025-66478 CVE-2025-55182CVE-2025-55182
Target & Sectors
NORTH_AMERICA NORTH_AMERICA energyenergy governmentgovernment financefinance defensedefense
Incident Timeline
Dec. 3, 2025
Hackers used a new tool to scan for React2Shell exposure.
organisation CVE-2025-55182
tactic Remote Code Execution
tactic T1584.004 - Server
2026-02-20
Chinese state-sponsored attackers began exploiting React2Shell, a vulnerability in React Server Components with a CVSS v3.x score of 10.0 and a CVSS v4 score of 9.3, in cloud and enterprise environments shortly after its disclosure.
organisation CVE-2025
organisation Earth Lamia
organisation Google
organisation CVSS
infrastructure 19.0
infrastructure 19.1.0
infrastructure 19.1.1
infrastructure 19.2.0
organisation CVE
organisation Observed Exploitation Activity Since
organisation CVE-2025-55182
organisation RSC
infrastructure Linux
organisation ELF
organisation NSS
organisation FRP
infrastructure Windows
organisation MINOCAT
organisation HISONIC
organisation COMPOOD
organisation XMRIG
organisation GitHub
organisation UNC5454
organisation VSHELL
organisation the Bank of New York Mellon
organisation Goldman Sachs
organisation Santander US Capital Markets
organisation JPMorgan Chase
organisation Salesforce
organisation Visa
organisation Disney Energy
organisation React2Shell Exposure
organisation Huntress
organisation Claude Code Put Developers' Machines
organisation React2Shell
organisation PeerBlight
organisation the BitTorrent DHT
organisation Log4Shell
organisation IP
organisation React2Shell Patching
Dec. 12
Threat actors used a new tool to scan for potential React2Shell exposure in China-nexus targeted networks.
source_region China
vulnerability CVE-2025-55182
organisation China-Nexus Activity As
Tactical Metrics
Metrics
infrastructure
​19.0
Software Version
Metrics
infrastructure
​19.1.0
Software Version
Metrics
infrastructure
​19.1.1
Software Version
Metrics
infrastructure
​19.2.0
Software Version
Metrics
infrastructure
​Linux
Affected Product
Metrics
infrastructure
​Windows
Affected Product
Intelligence Sources