BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

React2Shell Vulnerability Exploited for Linux Malware Attacks

React2Shell Vulnerability Exploited Globally to Deploy Advanced Malware and Steal Cloud Credentials

  • The React2Shell security vulnerability is actively exploited to deploy advanced Malware such as KSwapDoor and ZnDoor.
  • KSwapDoor is a stealthy Linux remote access tool using encrypted mesh networking and a “sleeper” mode to avoid firewalls.
  • Multiple threat actor groups, including at least five China-linked ones, utilize React2Shell to deliver various payloads targeting cloud and enterprise systems.
  • Attackers harvest cloud and AI credentials using tools like TruffleHog and Gitleaks to deepen access in compromised environments.
  • Over 111,000 IPs remain vulnerable to React2Shell, with thousands of ongoing exploit attempts worldwide as tracked by security organizations.

A critical security flaw named React2Shell is being exploited by cybercriminals to deliver harmful malware such as the remote access tool KSwapDoor and backdoor ZnDoor. This exploitation has been ongoing since at least December 2023, with attacks targeting organizations globally, including those in Japan, where ZnDoor has been observed in the wild. The payload delivery often occurs via bash commands using wget to download and execute malicious code from remote servers.

- Advertisement -

KSwapDoor operates on Linux systems, creating an encrypted mesh network connecting compromised servers to evade detection and security blocks. Justin Moore, senior manager of threat intel research at Palo Alto Networks Unit 42, explained, “It uses military-grade encryption to hide its communications and features a ‘sleeper’ mode that lets attackers bypass firewalls by waking the malware up with a secret, invisible signal.” It also impersonates legitimate Linux kernel processes to avoid being flagged.

The React2Shell vulnerability is identified as CVE-2025-55182, carrying the maximum CVSS score of 10.0. Multiple threat actor groups with links to China have weaponized this exploit to deploy diverse payloads, including tunneling utilities (MINOCAT), downloaders (SNOWLIGHT), backdoors (COMPOOD and HISONIC), and remote access trojans such as ANGRYREBEL (also known as Noodle RAT).

Microsoft reported that attackers leverage the vulnerability to execute arbitrary commands, establish reverse shells to Cobalt Strike servers, deploy remote monitoring tools like MeshAgent, alter authorized_keys, and enable root login. The intruders also use Cloudflare Tunnel endpoints to obscure their activities. These attacks involve credential theft targeting cloud service metadata endpoints for platforms like Azure, AWS, Google Cloud Platform, and Tencent Cloud. Tools such as TruffleHog and Gitleaks assist in extracting sensitive secrets including AI service tokens (OpenAI API keys), Kubernetes service accounts, and various cloud-native credentials.

A campaign known as Operation PCPcat has compromised over 59,000 servers by exploiting React2Shell and other Next.js vulnerabilities, stealing configuration files, SSH keys, cloud credentials, and system data. The malware establishes persistence, deploys SOCKS5 proxies, and creates reverse shells for ongoing control and propagation, showing signs of extensive intelligence-driven data exfiltration.

- Advertisement -

Current tracking by the Shadowserver Foundation reveals more than 111,000 IP addresses vulnerable to React2Shell, with the highest numbers in the United States, Germany, France, and India. Security telemetry from GreyNoise identifies over 500 malicious IPs actively attempting exploitation in the past 24 hours across the U.S., India, the U.K., Singapore, and the Netherlands.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bittrex Seeks $24M SEC Settlement Refund After Policy Shift

Defunct crypto exchange Bittrex is asking a federal judge to overturn its 2023 settlement...

Witkoff Backs Tether CEO’s ‘Trillions of Agents’ Crypto Future

World Liberty Financial is expanding rapidly into stablecoins and tokenized assets, positioning USD-backed stablecoins...

Strategy’s Saylor reverses stance, may sell Bitcoin for dividends

Michael Saylor's company, Strategy (formerly MicroStrategy), announced on its Q1 2026 earnings call that...

ETH Accumulation Surges $592M, Targets $3,315

Ethereum accumulation addresses absorbed $592 million worth of ETH on Wednesday, signaling aggressive long-term...

Apple Stock Forecast: When, Not If, $300 Breaks as Analysts Up Targets

Apple stock trades at $284.18 on May 6, with analysts shifting focus from *if*...

Must Read

Ethereum Hosting: TOP 10 Companies to Buy Hosting With Ethereum

If you are looking for Ethereum Hosting, you've hit the jackpot. In this article, we will present the 10 Best companies to buy hosting...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading