China-nexus threat groups observed (per AWS and other public reporting) experimenting with and exploiting CVE-2025-55182 (aka React2Shell), a critical unauthenticated RCE in the React Server Components (RSC) “Flight” protocol affecting default configurations of Next.js/App Router and other frameworks bundling react-server. Activity includes exploitation via crafted HTTP requests to achieve server-side code execution, followed by post-exploitation actions focused on cloud credential harvesting (e.g., searching environment variables, filesystem artifacts, and cloud instance metadata; attempting to identify/exfiltrate AWS credentials) and opportunistic cryptocurrency mining (including XMRig deployments, sometimes UPX-packed or downloaded from GitHub with specified mining pools). Reporting notes exploitation in the wild beginning early December 2024, with automated scanning/exploitation infrastructure also observed. The provided content does not name specific sub-groups or additional aliases beyond the generic “China-nexus groups,” nor does it attribute the EtherRAT blockchain-C2 implant to these China-nexus actors (it is described as overlapping with DPRK-linked tooling).
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-nexus groups rapidly exploited the React2Shell vulnerability (CVE-2025-55182) to deploy commodity backdoors and credential stealers, focusing on initial access and credential theft rather than long-term persistence.
China-nexus threat actors rapidly weaponized a critical vulnerability in React, referred to as 'React2Shell', shortly after its public disclosure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.