HomeSecurityReact2Shell exploit distributes crypto miners

React2Shell exploit distributes crypto miners

The React2Shell continues to be heavily observed, with malicious actors leveraging the critical security vulnerability in React Server Components (RSC) to distribute crypto miners and a number of previously undocumented malware families, according to new discoveries from Huntress.

See also: Crypto user loses $9,000 in seconds after clicking on Instagram ad

React2Shell
React2Shell exploit distributes crypto miners

This includes a Linux backdoor called PeerBlight, a reverse proxy tunnel called CowTunnel , and a post-exploit implant based on the Go language referred to as ZinFoq.

The cybersecurity firm said it has observed attackers targeting numerous organizations via CVE-2025-55182, a critical security vulnerability in RSC that allows unauthenticated remote code execution. Since December 8, 2025, these efforts have targeted a wide range of sectors, most notably the construction and entertainment industries.

The first recorded attempt to exploit a Windows endpoint by Huntress dates back to December 4, 2025, when an unknown malicious actor exploited a vulnerable instance of Next.js to drop a shell script, followed by commands to drop a crypto miner and a Linux backdoor.

In two other cases, attackers were observed launching discovery commands and attempting to download various payloads from a command and control (C2) server. Some notable attacks also targeted Linux hosts to drop the XMRig and leveraged a publicly available GitHub tool to identify vulnerable instances of Next.js before launching the attack.

See also: Exposed JDWP interfaces lead to crypto mining and DDoS

React2Shell exploit distributes crypto miners
React2Shell exploit distributes crypto miners

A brief description of some of the payloads downloaded in these attacks is as follows:

– sex.sh: A bash script that retrieves XMRig 6.24.0 directly from GitHub.

– PeerBlight: A Linux backdoor that shares some code overlap with two malware families, RotaJakiro and Pink, that came to light in 2021. It installs a systemd service to ensure persistence and disguises itself as a “ksoftirqd” daemon process to evade detection.

– CowTunnel: A reverse proxy tunnel that initiates an outbound connection to Fast Reverse Proxy (FRP) controlled by attackers, effectively bypassing firewalls configured to only monitor incoming connections.

– ZinFoq: A Linux ELF binary that implements a meta-exploit framework with interactive shell capabilities, file operations, network displacement, and timestamp modification capabilities.

– d5.sh: An installation script responsible for deploying the Sliver C2 framework.

– fn22.sh: A variant of “d5.sh” with an additional self-update mechanism to retrieve a new version of the malware and restart it.

– wocaosinm.sh: A variant of the Kaiji DDoS malware that incorporates remote management, persistence, and evasion capabilities.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Hackers exploit Craft CMS vulnerability to install cryptominer

React2Shell exploit distributes crypto miners
React2Shell exploit distributes crypto miners

PeerBlight supports capabilities to establish communications with a hardcoded C2 server (“185.247.224[.]41:8443”), allowing it to upload, download, delete files, create a reverse shell, modify file permissions, execute arbitrary binaries, and update itself. The backdoor also uses a domain generation algorithm (DGA) and the BitTorrent Distributed Hash Table (DHT) as backup C2 mechanisms.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS