# Bissa Scanner Mass-Exploits React2Shell With AI Help

Published: 2026-04-22 · Severity: high · Sectors: financial-services, retail, technology
Canonical: https://vorant.io/reports/5c94f93d-4301-56fe-9660-359376e04f4c/bissa-scanner-mass-exploits-react2shell-with-ai-help

> An exposed server revealed the AI-assisted Bissa scanner operation, which exploited CVE-2025-55182 across 900+ organizations to harvest secrets from tens of thousands of .env files.

The DFIR Report identified an exposed operator server hosting the infrastructure behind Bissa scanner, a modular exploitation and credential-harvesting platform. The operator used Claude Code and OpenClaw as an AI-assisted harness to build, troubleshoot, and orchestrate the scanner, which conducted internet-scale scanning for CVE-2025-55182 (React2Shell, a Next.js flaw) and confirmed over 900 successful compromises. A secondary module targeted CVE-2025-9501, an unauthenticated command injection in the W3 Total Cache WordPress plugin, though no evidence of successful exploitation via that module was found.

Post-compromise, the operator harvested .env files and secrets spanning AI providers, cloud services, payment platforms, databases, and messaging systems, then triaged and validated access to prioritize high-value targets in financial services, cryptocurrency, and retail. Victim-specific data clusters included a tax/financial advisory firm (Plaid tokens, IRS transcripts, SSN/DOB data), a digital-asset/payments enterprise (Oracle Fusion export data), and a payroll/stablecoin platform (Fireblocks, HRIS data). Harvested .env archives were exfiltrated to an S3-compatible Filebase bucket, with over 30,000 distinct filenames and 65,000+ archived entries collected between April 10–21, 2026.

The investigation also exposed the operator's Telegram-based C2 and alerting infrastructure, tying the activity to a single individual publicly identifiable via the handle @BonJoviGoesHard (display name 'Dr. Tube'), who ran at least two Telegram bots for scanner alerting and AI-control. The report indicates a disciplined, long-running, repeatable operation converting mass internet scanning into validated, high-value compromises, with coordinated disclosures to affected organizations underway and law enforcement engaged.

## Mentioned in this report

- Vulnerabilities: CVE-2025-55182 (KEV), CVE-2025-9501
- Threat actors: Dr. Tube
- Malware: Bissa Scanner
- Campaigns: Bissa Scanner

Source reporting: https://thedfirreport.com/2026/04/22/bissa-scanner-exposed-ai-assisted-mass-exploitation-and-credential-harvesting

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5c94f93d-4301-56fe-9660-359376e04f4c/bissa-scanner-mass-exploits-react2shell-with-ai-help.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
