Iran-aligned attackers are a loosely defined set of threat actors assessed to operate in support of Iranian state interests or from an Iranian nexus. In the available reporting, they were observed exploiting the critical React remote code execution vulnerability CVE-2025-55182, also known as React2Shell, as part of broader mass exploitation activity affecting internet-facing React and related cloud-hosted workloads. The reporting confirms Iranian involvement in exploitation of the vulnerability but does not provide a more specific cluster name, malware family set, or sub-group attribution for these actors. Their observed activity in this context is consistent with rapid exploitation of newly disclosed server-side vulnerabilities for initial access and follow-on post-compromise operations. The vulnerability enabled unauthenticated remote code execution, allowing attackers to gain access to affected servers through a single crafted request. While multiple actor sets from several countries and financially motivated operators were seen abusing the same flaw, the Iranian-attributed activity is specifically supported only at the level of exploitation of the vulnerability itself. Because the attribution in this case remains broad, high-confidence characterization should be limited to exploitation for initial access and subsequent post-exploitation potential against cloud environments and workloads running vulnerable React components. More granular claims regarding victimology, malware tooling, persistence mechanisms, credential theft, or sector targeting are not directly established for this actor label in the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iran-aligned threat actors exploiting React2Shell for espionage and persistent access.
Exploiting React2Shell for espionage and persistent access.
Exploiting React2Shell for access and potential espionage.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.