HiddenOrbit, also referred to as RedRelay, is a Chinese anonymization relay network associated with state-sponsored cyber activity. It has been observed supporting rapid post-disclosure exploitation activity, including scanning and exploitation attempts against the React2Shell vulnerability (CVE-2025-55182) shortly after public disclosure. HiddenOrbit appears in reporting alongside other China-nexus intrusion sets that operationalized the flaw for initial access and follow-on compromise. The infrastructure associated with HiddenOrbit has been used for reconnaissance and exploitation rather than being described as a standalone malware family. In the React2Shell exploitation wave, China-nexus operators leveraged the vulnerability for unauthenticated remote code execution against exposed React Server Components and vulnerable Next.js deployments, followed by payload delivery and broader post-exploitation activity seen across the cluster of actors using the flaw. Reported downstream behaviors in this campaign ecosystem included reconnaissance, malware staging, remote access tooling, web shell deployment, and cryptominer delivery. HiddenOrbit is best understood as infrastructure tied to Chinese state-sponsored operations and used to relay or anonymize offensive traffic. The alias RedRelay is associated with the same activity. High-confidence reporting supports its role in scanning and exploitation operations against internet-exposed targets, particularly in the immediate aftermath of major vulnerability disclosure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated in the report’s aggregated section with exploitation activity around React2Shell (CVE-2025-55182) and related RSC/Next.js vulnerabilities.
Named in an aggregated list of actors associated with React2Shell (CVE-2025-55182) exploitation activity.
Provides anonymization relay infrastructure for Chinese state-sponsored threat actors to conduct scanning and exploitation of CVE-2025-55182.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.