ZnDoor is a remote access trojan (RAT) observed in the wild since at least December 2023 and deployed in attacks exploiting the React2Shell vulnerability (CVE-2025-55182) in React/Next.js applications. Reporting cited in the content states that organizations in Japan have been targeted, with initial React2Shell exploitation used for cryptomining before escalating to ZnDoor deployment for persistent access. The attack chain described involves exploitation of React2Shell to execute shell commands that download and run ZnDoor from 45.76.155.14, after which the malware establishes encrypted command-and-control communications with api.qtss.cc:443.
ZnDoor provides broad post-compromise control. High-confidence capabilities mentioned in the content include shell command execution, file operations, system information gathering and enumeration, proxying and port forwarding, and SOCKS5 proxy activation. It reportedly beacons to its C2 every second over HTTP POST, sending host information, and parses tasking using double-hash delimiters. The malware encrypts configuration data, including C2 address and port, using AES-CBC after Base64 decoding.
The malware also employs multiple evasion and anti-forensic techniques. The content states that ZnDoor spoofs process names to masquerade as legitimate system processes, modifies file timestamps to January 15, 2016, and uses self-restart mechanisms with child processes to complicate analysis. ZnDoor has been referenced alongside other malware families delivered via React2Shell, and broader reporting in the content associates React2Shell exploitation with multiple China-nexus threat groups; however, the provided content does not directly attribute ZnDoor itself to a specific actor with high confidence. Known indicators explicitly mentioned in the content include the download host 45.76.155.14 and C2 endpoint api.qtss.cc:443.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
1 distinct technique documented for this family, organized by ATT&CK tactic.
49 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux backdoor delivered via exploitation of React2Shell.
Named RAT referenced among payloads/tools seen in React2Shell exploitation activity (no additional behavior described in the provided content).
ZnDoor is a backdoor malware executed by the React2Shell exploit, providing remote access to compromised systems.
ZnDoor is a backdoor malware that can be executed via the React2Shell exploit, providing attackers with remote access to compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.