{"id":9196,"date":"2025-12-14T10:03:36","date_gmt":"2025-12-14T10:03:36","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/14\/google-warns-multiple-hacker-groups-are-exploiting-react2shell-to-spread-malware\/"},"modified":"2025-12-14T10:03:36","modified_gmt":"2025-12-14T10:03:36","slug":"google-warns-multiple-hacker-groups-are-exploiting-react2shell-to-spread-malware","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/14\/google-warns-multiple-hacker-groups-are-exploiting-react2shell-to-spread-malware\/","title":{"rendered":"Google Warns Multiple Hacker Groups Are Exploiting React2Shell to Spread Malware"},"content":{"rendered":"<p>    Google Warns Multiple Hacker Groups Are Exploiting React2Shell to Spread Malware<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Google Threat Intelligence Group (GTIG) has issued a warning regarding the widespread exploitation of a critical security flaw in <a href=\"https:\/\/cybersecuritynews.com\/poc-exploit-react-next-js\/\" target=\"_blank\" rel=\"noreferrer noopener\">React Server Components<\/a>. <\/p>\n<p>Known as\u00a0React2Shell (<a href=\"https:\/\/cybersecuritynews.com\/react2shell-cve-2025-55182-attacks-rsc-enabled-services\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-55182<\/a>), this vulnerability allows attackers to take control of servers remotely without needing a password.<\/p>\n<p>Since the vulnerability was disclosed on December 3, 2025, Google has observed multiple distinct hacker groups abusing the flaw. <\/p>\n<p>The attackers range from state-sponsored espionage groups to cybercriminals looking for financial gain.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-threat-actors-and-malware-campaigns\"><strong>Threat Actors and Malware Campaigns<\/strong><\/h2>\n<p>Google researchers have <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/threat-actors-exploit-react2shell-cve-2025-55182\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified <\/a>several campaigns targeting unpatched systems. Key observations include:<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>China-Nexus Espionage:<\/strong>\u00a0Groups linked to China are using React2Shell to deploy backdoors and stealthy tools. One group,\u00a0UNC6600, installs the\u00a0MINOCAT\u00a0tunneler to maintain hidden access to victim networks. Another group,\u00a0UNC6603, uses an updated version of the\u00a0HISONIC\u00a0backdoor, which hides its traffic by communicating through legitimate services like Cloudflare.<\/li>\n<li>\n<strong>Financial Cybercrime<\/strong>:\u00a0Opportunistic attackers are using the flaw to install cryptocurrency miners. In one case, criminals deployed\u00a0XMRig\u00a0to generate digital currency using the victim\u2019s server power.<\/li>\n<li>\n<strong>Additional Threats:<\/strong>\u00a0Other identified malware includes the\u00a0SNOWLIGHT\u00a0downloader and the\u00a0COMPOOD\u00a0backdoor, both used to steal data or load further malicious software.<\/li>\n<\/ul>\n<p>React2Shell is rated with a maximum severity score of\u00a010.0 (CVSS v3). It affects specific versions of <a href=\"https:\/\/cybersecuritynews.com\/scanner-tool-reactjs-and-next-js\/\" target=\"_blank\" rel=\"noreferrer noopener\">React and Next.js<\/a>, popular frameworks used to build modern websites. Because these tools are widely used, many organisations are currently exposed.<\/p>\n<p>Google warns that legitimate exploit code is now publicly available, making it easier for attackers to strike. <\/p>\n<p>While some early exploit tools were fake or broken, functional methods including tools that can install web shells directly into memory are now in circulation.<\/p>\n<p>Security experts urge administrators to patch affected systems immediately. Organizations using\u00a0Next.js\u00a0or\u00a0React Server Components\u00a0should verify they are running secure versions to prevent unauthorized access.<\/p>\n<p><strong>IoC<\/strong><\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>Indicator<\/strong><\/td>\n<td><strong>Type<\/strong><\/td>\n<td><strong>Description<\/strong><\/td>\n<\/tr>\n<tr>\n<td><code>reactcdn.windowserrorapis[.]com<\/code><\/td>\n<td>Domain<\/td>\n<td>SNOWLIGHT\u00a0C2 and Staging Server<\/td>\n<\/tr>\n<tr>\n<td><code>82.163.22[.]139<\/code><\/td>\n<td>IP Address<\/td>\n<td>SNOWLIGHT\u00a0C2 Server<\/td>\n<\/tr>\n<tr>\n<td><code>216.158.232[.]43<\/code><\/td>\n<td>IP Address<\/td>\n<td>Staging server for sex.sh script<\/td>\n<\/tr>\n<tr>\n<td><code>45.76.155[.]14<\/code><\/td>\n<td>IP Address<\/td>\n<td>COMPOOD\u00a0C2 and Payload Staging Server<\/td>\n<\/tr>\n<tr>\n<td><code>df3f20a961d29eed46636783b71589c183675510737c984a11f78932b177b540<\/code><\/td>\n<td>SHA256<\/td>\n<td>HISONIC\u00a0sample<\/td>\n<\/tr>\n<tr>\n<td><code>92064e210b23cf5b94585d3722bf53373d54fb4114dca25c34e010d0c010edf3<\/code><\/td>\n<td>SHA256<\/td>\n<td>HISONIC\u00a0sample<\/td>\n<\/tr>\n<tr>\n<td><code>0bc65a55a84d1b2e2a320d2b011186a14f9074d6d28ff9120cb24fcc03c3f696<\/code><\/td>\n<td>SHA256<\/td>\n<td>ANGRYREBEL.LINUX\u00a0sample<\/td>\n<\/tr>\n<tr>\n<td><code>13675cca4674a8f9a8fabe4f9df4ae0ae9ef11986dd1dcc6a896912c7d527274<\/code><\/td>\n<td>SHA256<\/td>\n<td>XMRIG\u00a0Downloader Script\u00a0(filename: sex.sh)<\/td>\n<\/tr>\n<tr>\n<td><code>7f05bad031d22c2bb4352bf0b6b9ee2ca064a4c0e11a317e6fedc694de37737a<\/code><\/td>\n<td>SHA256<\/td>\n<td>SNOWLIGHT\u00a0sample (filename: linux_amd64)<\/td>\n<\/tr>\n<tr>\n<td><code>776850a1e6d6915e9bf35aa83554616129acd94e3a3f6673bd6ddaec530f4273<\/code><\/td>\n<td>SHA256<\/td>\n<td>MINOCAT\u00a0sample<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/google-warns-exploiting-react2shell-to-spread-malware\/\">Google Warns Multiple Hacker Groups Are Exploiting React2Shell to Spread Malware<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Dhivya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/google-warns-exploiting-react2shell-to-spread-malware\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Google Warns Multiple Hacker Groups Are Exploiting React2Shell to Spread Malware Google Threat Intelligence Group (GTIG) has issued a warning regarding the widespread exploitation of a critical security flaw in React Server Components. Known as\u00a0React2Shell (CVE-2025-55182), this vulnerability allows attackers to take control of servers remotely without needing a password. Since the vulnerability was disclosed [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,163,258,131],"tags":[130],"class_list":["post-9196","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-google","category-malware","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9196"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9196"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9196\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9196"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9196"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9196"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}