UAT-10608 is a threat cluster associated with a large-scale automated credential-harvesting campaign targeting internet-exposed Next.js applications vulnerable to React2Shell (CVE-2025-55182), with downstream exposure also tracked in Next.js as CVE-2025-66478. The actor’s operations are characterized by indiscriminate internet-wide scanning for vulnerable deployments, followed by unauthenticated remote code execution through crafted requests to Server Function endpoints in environments using React Server Components. After initial compromise, the actor deploys an automated multi-phase collection workflow and manages victim data through a custom web-based platform known as NEXUS Listener, observed as version 3. The cluster’s primary activity is theft and aggregation of sensitive access material from compromised servers. Reported collection includes passwords, cloud credentials and tokens, database credentials and connection strings, SSH private keys, GitHub and GitLab tokens, Kubernetes service account credentials, package registry authentication material, environment variables, shell histories, process data, and container configuration details. The actor also harvests cloud metadata-derived credentials from major cloud environments, creating risk of cloud account takeover, follow-on intrusion, and lateral movement. Theft of software repository credentials introduces software supply-chain risk through potential abuse of trusted package publishing accounts. Operationally, UAT-10608 appears highly automated. The intrusion chain includes reconnaissance to identify exposed vulnerable applications, exploitation for initial access, deployment of a lightweight dropper, execution of harvesting scripts, and exfiltration of collected data to actor-controlled infrastructure. NEXUS Listener functions as both command-and-control and an analytics interface, allowing operators to browse compromised hosts, search stolen data, and review harvesting statistics at scale. Observed victimology spans multiple geographic regions and cloud providers, and available reporting characterizes targeting as broad and opportunistic rather than narrowly sector-specific. No high-confidence attribution to a nation state or specific country of origin is currently available from the supplied facts. The dominant observed motivation is financial, based on systematic theft of credentials and access material that could support access resale, account takeover, fraud, or downstream monetization.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The vulnerability at the center of this attack is CVE-2025-55182, widely known as React2Shell. Rated a maximum severity score of 10.0 on the CVSS scale, the flaw exists in the React Server Components (RSC) Flight protocol, specifically in how a React server processes HTTP requests to Server Function endpoints. A single crafted HTTP request is enough for an attacker to execute code on the server with no authentication required.
Next.js also received a separate tracking number, CVE-2025-66478, given its significant downstream exposure to this flaw.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a large-scale, automated exploitation campaign against vulnerable Next.js/React Server Components deployments to achieve unauthenticated remote code execution and harvest credentials and sensitive data from compromised servers.
Conducting a global, cross-industry credential theft campaign by exploiting vulnerable public-facing Next.js applications via React2Shell, then deploying NEXUS Listener to exfiltrate credentials, SSH keys, cloud tokens, and environment secrets at scale for follow-on malicious activity.
Conducting a large-scale automated credential-harvesting campaign by exploiting React2Shell (CVE-2025-55182) in vulnerable Next.js applications, using the NEXUS Listener framework to collect and exfiltrate secrets from compromised hosts.
Conducting a large-scale automated credential theft campaign against vulnerable Next.js web applications by exploiting React2Shell to gain initial access and harvest credentials from servers, cloud environments, databases, and developer platforms.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.