Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareExploits 1 CVE

COMPOOD

COMPOOD is a backdoor used in suspected China-nexus espionage activity (linked in reporting since at least 2022). It has been observed delivered by the China-nexus cluster UNC6588, including in campaigns exploiting the React Server Components RCE vulnerability CVE-2025-55182 (“React2Shell”). In the described intrusions, attackers used wget to download and execute the COMPOOD payload, and it was reported to masquerade as a legitimate binary to maintain persistent access. Reporting also notes COMPOOD is used to steal data and/or to load additional malicious software. No additional high-confidence host/network indicators specific to COMPOOD (e.g., hashes, C2 domains) are provided in the supplied content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2025-55182React2ShellExploited in the wild

On Dec. 3, 2025, a critical unauthenticated remote code execution (RCE) vulnerability in React Server Components, tracked as CVE-2025-55182 (aka "React2Shell"), was publicly disclosed. Shortly after disclosure, Google Threat Intelligence Group (GTIG) had begun observing widespread exploitation...

via mandiant threat intelligencecloud.google.com
MITRE ATT&CK

Techniques & procedures

1 distinct technique documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1190Exploit Public-Facing ApplicationEvidence2

“React2Shell exploitation continues… globally exploited… victims triaged… distinct campaigns leveraging this vulnerability…” and “threat actor use React2Shell as the initial access vector in a ransomware attack.”

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping1

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.