HomeSecurityReact2Shell vulnerability used to install Linux Backdoors

React2Shell vulnerability used to install Linux Backdoors

The React2Shell is being used by malicious actors to deliver the KSwapDoor and ZnDoor malware, according to findings from Palo Alto Networks Unit 42 and NTT Security.

React2Shell Linux

“KSwapDoor is a professionally designed tool remote access built with stealth in mind,” said Justin Moore, senior director of threat research at Palo Alto Networks Unit 42. “It creates an internal mesh network, allowing compromised servers to communicate with each other and bypass security blocks. It uses military-grade encryption to hide its communications and, most worryingly, has a ‘sleeper’ mode that allows attackers to bypass firewalls by activating the malware with a secret, invisible signal.”

See also: FreePBX fixes critical vulnerabilities that allow RCE attack

The cybersecurity firm noted that it was previously misclassified as BPFDoor, adding that the Linux backdoor offers interactive shell capabilities, command execution, file operations, and lateral movement. It also pretends to be a legitimate Linux kernel swap daemon to evade detection.

In a related development, NTT Security reported that organizations in Japan have been targeted by cyberattacks exploiting React2Shellto deploy ZnDoor, a malware discovered in December 2023. The attack chains include executing a bash command to retrieve the payload from a remote server (using wget and executing it).

React2Shell vulnerability used to install Linux Backdoors

React2Shell Exploit – Malware Distribution

A remote access trojan communicates with the same infrastructure, controlled by the malicious actor, to receive commands and execute them on the host computer. Some of the supported commands include:

– shell: to execute a command

– interactive_shell: to start an interactive shell

– explorer: to obtain a list of directories

– explorer_cat: for reading and displaying a file

– explorer_delete: to delete a file

– explorer_upload: for downloading a file from the server

– explorer_download: for sending files to the server

– system: to collect system information

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

– change_timefile: to change the timestamp of a file

– socket_quick_startstreams: for starting a SOCKS5 server

– start_in_port_forward: to start port forwarding

– stop_in_port: to stop port forwarding

See also: Vulnerability in Plesk allows root access

The revelation comes as the vulnerability, tracked as CVE-2025-55182 (CVSS score: 10.0), has been exploited by multiple malicious actors, with Google identifying at least five Chinese groups that have used it to deliver a range of payloads:

– UNC6600 for the delivery of a tunneling utility named MINOCAT

– UNC6586 for the delivery of a downloader named SNOWLIGHT

– UNC6588 for delivering a backdoor named COMPOOD

– UNC6603 for delivering an updated version of a Go backdoor named HISONIC, which uses Cloudflare Pages and GitLab to retrieve encrypted settings and integrate with legitimate network activity

– UNC6595 for delivering a Linux version of ANGRYREBEL (aka Noodle RAT)

React2Shell vulnerability used to install Linux Backdoors

Microsoft, in its own advisory for CVE-2025-55182, reported that malicious actors have exploited the vulnerability to execute arbitrary commands and install tools remote monitoring and management (RMM) such as MeshAgent.

See also: Windows RasMan vulnerability allows arbitrary code execution

Some of the payloads delivered in these attacks include VShell, EtherRAT, SNOWLIGHT, ShadowPad, and XMRig. The attacks are also characterized by the use of Cloudflare Tunnel endpoints (“*.trycloudflare.com”) to evade security defenses, as well as conducting reconnaissance to facilitate lateral movement and credential theft.

The credential harvesting activity targeted Azure Instance Metadata Service (IMDS) endpoints for Azure, Amazon Web Services (AWS), Google Cloud Platform (GCP), and Tencent Cloud, with the ultimate goal of obtaining identities to penetrate deeper into cloud infrastructures.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS