North Korean-linked threat actors have exploited the critical React2Shell vulnerability (CVE-2025-55182) in React Server Components to deploy a new malware implant known as EtherRAT. EtherRAT features advanced capabilities, including five independent Linux persistence mechanisms, blockchain-based command-and-control using Ethereum smart contracts, and the ability to download its own Node.js runtime. The attack chain begins with remote code execution via a crafted HTTP request, followed by the download and execution of a malicious shell script that prepares the environment and deploys the main JavaScript implant. Researchers note significant overlap with the "Contagious Interview" campaign, which targets blockchain and Web3 developers through fake job offers and coding assignments, but EtherRAT introduces new technical distinctions.
The exploitation of React2Shell began within hours of the vulnerability's public disclosure, with both North Korean and China-linked groups observed leveraging the flaw. Automated attacks have compromised at least 30 organizations across multiple sectors, resulting in credential theft, cryptomining, and the deployment of commodity backdoors. The EtherRAT campaign demonstrates the rapid weaponization of newly disclosed vulnerabilities and the increasing sophistication of North Korean cyber operations, particularly in targeting cloud environments and the JavaScript ecosystem.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
A blue-team lab writeup states that on 2026-02-10 an attacker exploited a public-facing Next.js application at Maromalix via CVE-2025-55182, downloaded an s.sh script, and installed the EtherRAT implant. The writeup says the malware resolved C2 through Ethereum smart contracts, exfiltrated credentials, and established persistence via a systemd user service and an injected SSH key.
Security researchers recommended immediate upgrades to patched React and Next.js versions as the only definitive mitigation for CVE-2025-55182. They also published indicators of compromise and detection guidance, including monitoring for Ethereum RPC traffic and Linux persistence artifacts tied to EtherRAT.
Unit 42 disclosed additional Linux backdoors seen in the React2Shell exploitation ecosystem, including Auto-color masquerading as a PAM library and a newly characterized backdoor named KSwapDoor. KSwapDoor was described as a stealthy persistent Linux server backdoor using a peer-to-peer mesh C2 design and masquerading as a kernel swap daemon.
Palo Alto Networks Unit 42 reported that post-exploitation activity included a China-nexus cluster, CL-STA-1015, associated in reporting with UNC5174, using fileless shell scripts to deploy SNOWLIGHT and VShell. It also noted separate activity overlapping DPRK Contagious Interview tooling involving EtherRAT and EtherHiding, without formal attribution.
Sysdig publicly reported EtherRAT as a new malware family deployed through React2Shell and said its tradecraft overlapped with North Korean Contagious Interview and Lazarus-associated tooling. The reporting highlighted blockchain-based C2, self-updating payloads, and a shell-script-to-JavaScript attack chain.
By early December, at least 30 organizations across multiple sectors had reportedly been breached through React2Shell exploitation. Observed attacker actions included credential theft, cloud configuration theft attempts, cryptominer deployment, and installation of backdoors.
Shortly after disclosure, researchers recovered a new malware implant named EtherRAT from a compromised Next.js application exploited via React2Shell. The implant used Ethereum smart contracts for command-and-control and included multiple Linux persistence mechanisms.
Following evidence of active exploitation, CISA added CVE-2025-55182 to its Known Exploited Vulnerabilities list. This reflected the rapid operationalization of the flaw by threat actors.
Researchers observed exploitation activity within hours of the December 3 disclosure, including automated scanning and early post-compromise activity. China-linked groups such as Earth Lamia and Jackpot Panda were reported among the first observed actors.
The critical unauthenticated remote code execution flaw in React Server Components' Flight protocol, tracked as CVE-2025-55182 and dubbed React2Shell, was publicly disclosed. The issue affected React 19 and related frameworks including Next.js.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 100 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
9 references tracked. Mallory keeps watching after this page renders.
infosecwriteups.com
Open sourceunit42.paloaltonetworks.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcehackread.com
Open sourcesecurityonline.info
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourceetherscan.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.