Cisco Talos reported that threat cluster UAT-10608 exploited the critical Next.js React2Shell vulnerability, tracked as CVE-2025-55182 with a CVSS 10.0, to compromise at least 766 internet-exposed hosts across multiple regions and cloud providers. The campaign appears to be broad and automated, with attackers likely using internet-scanning services to find vulnerable deployments before gaining remote code execution and installing a dropper plus a multi-stage credential-harvesting framework called NEXUS Listener.
Investigators said the malware collected secrets from files, cloud settings, system memory, shell history, containers, and SSH material, then exposed the loot through a password-protected web dashboard that allowed operators to browse victims and search stolen data. Observed data included AWS credentials, private SSH keys, database connection strings, GitHub and GitLab tokens, Stripe keys, SendGrid and Brevo secrets, Telegram bot tokens, and credentials for OpenAI, Anthropic, and NVIDIA NIM, raising risks of cloud takeover, lateral movement, software supply chain abuse, follow-on intrusions, and resale of access; defenders were urged to patch vulnerable Next.js systems, rotate exposed credentials, restrict metadata service access, and monitor for suspicious background processes.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The DFIR Report uncovered exposed attacker infrastructure showing the React2Shell campaign had compromised more than 900 companies worldwide and used Telegram bots for near-real-time victim triage. Researchers also observed more than 65,000 archived file entries uploaded to a Filebase bucket named "bissapromax" between April 10 and April 21, 2026, revealing expanded scale and additional operational tradecraft.
Cisco Talos published findings on the UAT-10608 operation, warning that the indiscriminate theft of aggregated credentials could enable follow-on intrusions, social engineering, cloud compromise, and resale of access. Reporting also urged organizations to patch vulnerable Next.js applications, rotate exposed secrets, and monitor for suspicious processes.
Cisco Talos reported that the campaign had compromised at least 766 hosts across multiple regions and cloud providers, with one exposed NEXUS Listener instance showing 766 affected hosts within a 24-hour period. Observed stolen data included Stripe keys, AWS credentials, GitHub and GitLab tokens, database connection strings, and credentials for services such as OpenAI, Anthropic, NVIDIA NIM, SendGrid, Brevo, and Telegram.
After gaining access, the attackers deployed a dropper and a multi-stage harvesting toolkit called NEXUS Listener to collect secrets, cloud credentials, SSH keys, shell history, container data, and other sensitive information from infected systems. The framework included a password-protected web interface for browsing compromised hosts and reviewing stolen data.
A threat cluster tracked as UAT-10608 began exploiting the critical React2Shell remote code execution flaw, CVE-2025-55182, to gain initial access to internet-exposed Next.js deployments. Cisco Talos assessed the activity as broad and likely automated, using internet scanning to find vulnerable hosts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcedarkreading.com
Open sourcebleepingcomputer.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcethreats.wiz.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.