COMPOOD
COMPOOD is a backdoor used in suspected China-nexus espionage activity (linked in reporting since at least 2022). It has been observed delivered by the China-nexus cluster UNC6588, including in campaigns exploiting the React Server Components RCE vulnerability CVE-2025-55182 (“React2Shell”). In the described intrusions, attackers used wget to download and execute the COMPOOD payload, and it was reported to masquerade as a legitimate binary to maintain persistent access. Reporting also notes COMPOOD is used to steal data and/or to load additional malicious software. No additional high-confidence host/network indicators specific to COMPOOD (e.g., hashes, C2 domains) are provided in the supplied content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Vulnerabilities exploited
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On Dec. 3, 2025, a critical unauthenticated remote code execution (RCE) vulnerability in React Server Components, tracked as CVE-2025-55182 (aka "React2Shell"), was publicly disclosed. Shortly after disclosure, Google Threat Intelligence Group (GTIG) had begun observing widespread exploitation...
Techniques & procedures
1 distinct technique documented for this family, organized by ATT&CK tactic.
Recent activity
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor deployed in campaigns exploiting React2Shell (CVE-2025-55182) per the referenced reporting.
A backdoor delivered by UNC6588, used for persistent remote access and control.
Compood is a backdoor deployed after exploitation of CVE-2025-55182, likely used for remote access and further malicious activity.
COMPOOD is a backdoor payload deployed by the Chinese threat group UNC6588, providing persistent remote access to compromised systems via the React2Shell vulnerability.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.