Bissa Scanner Mass-Exploits React2Shell With AI Help
An exposed server revealed the AI-assisted Bissa scanner operation, which exploited CVE-2025-55182 across 900+ organizations to harvest secrets from tens of thousands of .env files.
The DFIR Report identified an exposed operator server hosting the infrastructure behind Bissa scanner, a modular exploitation and credential-harvesting platform. The operator used Claude Code and OpenClaw as an AI-assisted harness to build, troubleshoot, and orchestrate the scanner, which conducted internet-scale scanning for CVE-2025-55182 (React2Shell, a Next.js flaw) and confirmed over 900 successful compromises. A secondary module targeted CVE-2025-9501, an unauthenticated command injection in the W3 Total Cache WordPress plugin, though no evidence of successful exploitation via that module was found.
Post-compromise, the operator harvested .env files and secrets spanning AI providers, cloud services, payment platforms, databases, and messaging systems, then triaged and validated access to prioritize high-value targets in financial services, cryptocurrency, and retail. Victim-specific data clusters included a tax/financial advisory firm (Plaid tokens, IRS transcripts, SSN/DOB data), a digital-asset/payments enterprise (Oracle Fusion export data), and a payroll/stablecoin platform (Fireblocks, HRIS data). Harvested .env archives were exfiltrated to an S3-compatible Filebase bucket, with over 30,000 distinct filenames and 65,000+ archived entries collected between April 10–21, 2026.
The investigation also exposed the operator's Telegram-based C2 and alerting infrastructure, tying the activity to a single individual publicly identifiable via the handle @BonJoviGoesHard (display name 'Dr. Tube'), who ran at least two Telegram bots for scanner alerting and AI-control. The report indicates a disciplined, long-running, repeatable operation converting mass internet scanning into validated, high-value compromises, with coordinated disclosures to affected organizations underway and law enforcement engaged.
Mentioned in this report
Source reporting: https://thedfirreport.com/2026/04/22/bissa-scanner-exposed-ai-assisted-mass-exploitation-and-credential-harvesting
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free