Mass exploitation hits React2Shell RCE flaw
Within days of CVE-2025-55182 disclosure, multiple threat actors independently compromised servers via the React Server Components RCE, deploying miners, RATs, and backdoors.
JPCERT/CC documented a case where an unauthenticated remote code execution vulnerability in React Server Components (CVE-2025-55182), disclosed December 3, 2025, was weaponized and exploited by numerous independent threat actors within 48 hours. A single compromised server ended up hosting overlapping intrusions: coin miners installed first, followed by various RATs and backdoors, and website defacements warning victims to patch. Access logs showed suspicious POST requests consistent with React2Shell exploitation from over 100 distinct IP addresses in a three-day window, indicating exploitation was widespread rather than limited to this one incident.
Notable tooling recovered included the SNOWLIGHT downloader (previously linked to UNC5174), a Golang-based HISONIC backdoor (linked to UNC6603), and CrossC2, a Linux-compatible Cobalt Strike beacon implementation, all deployed together — suggesting these actors may have been staging infrastructure for follow-on operations rather than acting purely opportunistically. The incident also featured abuse of the open-source tool Global Socket (gsocket), configured to tunnel a bash backdoor over port 53 (normally reserved for DNS) using a pre-shared key file for authentication — an unusual technique not commonly reported by other vendors covering this vulnerability.
This case illustrates the speed at which opportunistic and targeted actors alike weaponize newly disclosed, easily exploitable RCE vulnerabilities, and the risk of multiple overlapping compromises on a single asset. JPCERT/CC recommends that organizations patching CVE-2025-55182 also conduct compromise assessments, since visible symptoms like defacement may mask deeper, more consequential backdoor installations.
Mentioned in this report
Source reporting: https://blogs.jpcert.or.jp/en/2026/02/multiple-threat-actors-rapidly-exploit-react2shell-a-case-study-of-active-compromise.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free