Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
DFIR Report researchers discovered an exposed server running the 'Bissa scanner' operation, a large-scale exploitation campaign leveraging CVE-2025-55182 (React2Shell/Next.js RCE) to compromise 900+ organizations. The threat actor used Claude Code and OpenClaw as AI-assisted workflow orchestration tools to automate exploitation, triage victims, and harvest credentials. Over 30,000 distinct .env files were collected, yielding API keys for AI providers (Anthropic, OpenAI, Google), cloud platforms (AWS, Azure, Cloudflare), payment processors (Stripe, PayPal), and databases. Victims included financial, crypto, payroll, and retail organizations. The operator was identified via hardcoded Telegram bot tokens linking to the handle @BonJoviGoesHard. Defensive recommendations include aggressive patching, moving secrets out of .env files into secret managers, egress control, and credential rotation with canary tokens.