Huntress researchers detail active exploitation of CVE-2025-55182 (React2Shell), a CVSS 10.0 unauthenticated RCE vulnerability in React Server Components caused by insecure deserialization of the React Flight protocol. Threat actors are exploiting vulnerable Next.js instances across multiple sectors to deploy cryptominers (XMRig), a novel Linux backdoor called PeerBlight (which uses BitTorrent DHT as a resilient C2 fallback mechanism), a reverse proxy tunnel called CowTunnel (built on xfrpc), a Go-based post-exploitation implant called ZinFoq with SOCKS5 proxying and timestomping, and a Kaiji botnet variant. The post provides deep technical analysis of the exploit mechanism, attacker tradecraft across five cases, and detailed malware reverse engineering including PeerBlight's DHT-based C2 protocol, DGA algorithm, and persistence mechanisms. Immediate patching is recommended.

41m read timeFrom huntress.com
Post cover image
Table of contents
BackgroundExploit DetailsAttacker TradecraftPayload AnalysisMitigation GuidanceWhat is Huntress Doing?Sigma / Yara RulesIndicators of Compromise (IOCs)
3 Impressions