UAT-10608 is a threat cluster tracked by Cisco Talos and attributed to a large-scale, automated credential-harvesting campaign. The activity targeted publicly reachable Next.js web applications vulnerable to the React2Shell flaw (CVE-2025-55182), with downstream exposure in Next.js also tracked as CVE-2025-66478. Talos reported the campaign as indiscriminate and consistent with internet-wide automated scanning, likely using services such as Shodan or Censys or custom scanners to identify vulnerable hosts. According to the provided content, UAT-10608 exploited React Server Components / Server Function endpoints to achieve unauthenticated remote code execution via crafted HTTP requests, then deployed a lightweight dropper and multi-phase harvesting scripts. The operation used a custom web-based command-and-control and analytics framework called NEXUS Listener, observed as NEXUS Listener v3, to manage compromised hosts, browse stolen data, and review harvesting statistics. The campaign reportedly compromised at least 766 hosts within a 24-hour period across multiple geographic regions and cloud providers including AWS, Google Cloud, and Microsoft Azure. Stolen data included passwords, cloud access tokens and keys, AWS/GCP/Azure metadata and IAM credentials, database credentials and connection strings, SSH private keys and authorized_keys files, GitHub and GitLab tokens, Stripe live secret keys, Kubernetes service account credentials, package registry authentication files for npm and pip, environment variables, shell command histories, Docker/container configuration data, and running process information. The content notes that this created risks including cloud account takeover, lateral movement, access to sensitive services, and potential software supply-chain abuse through stolen package registry credentials. Known alias in the provided content: uat_10608. No nation-state attribution is stated in the provided material.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The vulnerability at the center of this attack is CVE-2025-55182, widely known as React2Shell. Rated a maximum severity score of 10.0 on the CVSS scale, the flaw exists in the React Server Components (RSC) Flight protocol, specifically in how a React server processes HTTP requests to Server Function endpoints. A single crafted HTTP request is enough for an attacker to execute code on the server with no authentication required.
Next.js also received a separate tracking number, CVE-2025-66478, given its significant downstream exposure to this flaw.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a large-scale, automated exploitation campaign against vulnerable Next.js/React Server Components deployments to achieve unauthenticated remote code execution and harvest credentials and sensitive data from compromised servers.
Conducting a global, cross-industry credential theft campaign by exploiting vulnerable public-facing Next.js applications via React2Shell, then deploying NEXUS Listener to exfiltrate credentials, SSH keys, cloud tokens, and environment secrets at scale for follow-on malicious activity.
Conducting a large-scale automated credential-harvesting campaign by exploiting React2Shell (CVE-2025-55182) in vulnerable Next.js applications, using the NEXUS Listener framework to collect and exfiltrate secrets from compromised hosts.
Conducting a large-scale automated credential theft campaign against vulnerable Next.js web applications by exploiting React2Shell to gain initial access and harvest credentials from servers, cloud environments, databases, and developer platforms.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.