Researchers reported an active campaign compromising NGINX servers to hijack and redirect legitimate user traffic through attacker-controlled backend infrastructure. The activity targets NGINX installations—particularly those managed via the Baota (BT) hosting panel—with an apparent focus on sites using Asian country-code TLDs and certain government/education domains (including .in, .id, .pe, .bd, .th, plus .edu and .gov).
The attackers modify existing NGINX configuration files by injecting malicious location blocks that match selected URL paths, rewrite requests to preserve the full original URL, and then forward traffic using proxy_pass to attacker-controlled domains. To reduce suspicion, the forwarded requests retain key headers (e.g., Host, X-Real-IP, User-Agent, Referer) so traffic appears legitimate, and the tooling reloads NGINX to avoid downtime. Datadog Security Labs described a scripted, multi-stage toolkit used to automate the configuration injection (including an initial controller with fallback download methods and a stage that enumerates common NGINX config locations) and published indicators of compromise to help defenders validate whether NGINX configurations have been tampered with.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Datadog Security Labs publicly reported the campaign, describing the multi-stage shell-script toolkit used to find targets, modify and validate NGINX configurations, reload services, and exfiltrate hijacked rule mappings to C2 server 158.94.210.227. The report also highlighted targeting of several Asian TLDs, plus .gov and .edu domains, and provided detection guidance.
An active campaign compromised NGINX servers, especially Baota (BT) Panel-managed deployments and common Linux/container layouts, by injecting malicious location blocks and proxy_pass directives into configuration files. The changes proxied selected legitimate requests through attacker-controlled backend servers while preserving headers to reduce detection.
In the months following disclosure, threat actors exploited React2Shell and used different post-exploitation payloads, including cryptomining retrieval and reverse shells. GreyNoise reported that two IP addresses accounted for most observed exploitation attempts.
The React2Shell vulnerability, tracked as CVE-2025-55182, was disclosed in late 2025. Later reporting tied the NGINX traffic-hijacking activity to threat actors associated with exploiting this flaw.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourcesecuritylabs.datadoghq.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.