Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The vulnerability at the center of this attack is CVE-2025-55182, widely known as React2Shell. Rated a maximum severity score of 10.0 on the CVSS scale, the flaw exists in the React Server Components (RSC) Flight protocol, specifically in how a React server processes HTTP requests to Server Function endpoints. A single crafted HTTP request is enough for an attacker to execute code on the server with no authentication required.
Next.js also received a separate tracking number, CVE-2025-66478, given its significant downstream exposure to this flaw.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Talos is disclosing a large-scale automated credential harvesting campaign carried out by a threat cluster we currently track as UAT-10608. The campaign is primarily leveraging a collection framework dubbed “NEXUS Listener.”
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Talos is disclosing a large-scale automated credential harvesting campaign carried out by a threat cluster we currently track as UAT-10608.
According to Cisco Talos researchers, the data stolen this way includes: ... Cloud credentials (AWS/GCP/Azure metadata, IAM credentials) ...
Several breached hosts exposed package registry authentication files, including npm and pip configuration files that carried registry credentials.
API keys IAM role-associated temporary credentials by querying the Instance Metadata Service for AWS, Google Cloud, and Microsoft Azure
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.