Pood is a backdoor malware family associated in the provided reporting with suspected China-nexus espionage activity. It was observed being deployed by the China-aligned cluster UNC6588, including in campaigns exploiting the React2Shell remote code execution vulnerability (CVE-2025-55182) affecting React and related frameworks. The content states that UNC6588 pushed a Pood backdoor payload and that Pood has historically been linked to suspected China-nexus espionage activity. In the broader exploitation activity described, China-nexus actors used Pood alongside other tooling such as SnowLight, VShell, and Hisonic while targeting cloud environments and workloads running vulnerable React and Next.js applications. No additional technical details, infection chain specifics beyond exploitation of CVE-2025-55182, or concrete indicators of compromise for Pood are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pood is a backdoor historically linked to China-nexus espionage activity, used to maintain access and control over compromised systems.
Pood is a backdoor historically linked to China-nexus espionage activity, used to maintain access and conduct further operations on compromised systems.
Pood is a backdoor historically linked to China-nexus espionage activity, used to maintain access and facilitate data exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.