PeerBlight is a Linux backdoor deployed in attacks exploiting the React Server Components remote-code-execution vulnerability CVE-2025-55182 (React2Shell). It has been observed against organizations including construction and entertainment-sector victims. PeerBlight establishes persistence through system service mechanisms, including alternatives for privileged and non-privileged execution, and disguises its process as a kernel-like daemon to reduce operator visibility. Its command set supports reverse shells, file download and upload, permission changes, file deletion, self-upgrade, execution and management of additional payloads, and configurable beacon intervals. PeerBlight uses encrypted command-and-control communications and incorporates multiple resilient fallback mechanisms: a domain-generation algorithm and configuration retrieval through the BitTorrent distributed hash table. The malware identifies associated nodes through a distinctive BitTorrent DHT node-ID convention and can receive signed command-and-control configuration updates through that network. It shares limited code and persistence-convention overlap with RotaJakiro and Pink, but is regarded as a distinct malware family with different protocol, encryption, and command structures.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints. | PeerBlight Linux Backdoor Exploits React2Shell
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The binary copies itself to /bin/systemd-daemon and enables the service using the generic "System Daemon" description.
The service masquerades as a legitimate SSH agent component, using the description "SSH Agent Service (System Management)" to blend in with authentic system services.
This backdoor uses the BitTorrent DHT network as a fallback C2 mechanism, making it resilient to traditional domain takedowns.
The payload, which we have named “ ZinFoq ” ... communicates with command-and-control infrastructure at “ api.qtss[.]cc ” over HTTPS using hex-encoded payloads
The threat actor attempted to download multiple payloads from C2 servers... The commands follow the same methodology: download a shell script, execute it via bash...
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux backdoor reported as exploiting the React2Shell remote-code-execution vulnerability.
Malware/tooling observed in post-exploitation that uses BitTorrent DHT as a resilient command-and-control fallback channel to maintain access even if domains are taken down.
Linux backdoor observed delivered in React2Shell exploitation activity.
Named backdoor referenced among payloads/tools seen in React2Shell exploitation activity (no additional behavior described in the provided content).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.