Hackers linked to the exploitation of the React2Shell vulnerability have tapped malicious NGINX configurations to divert web traffic from Asian top-level domains, government and educational TLDs, and Chinese hosting infrastructure to attacker-controlled infrastructure, The Hacker News reports.Illicit configurations have been injected into NGINX via shell scripts included in a multi-stage toolkit for persistence and the creation of more configuration files for web traffic hijacking, according to an analysis from Datadog Security Labs. Aside from shell scripts serving as an orchestrator for later attack stage execution and targeting the Baota Management Panel, the toolkit also features shell scripts enumerating typical NGINX configuration locations, prioritizing Linux or containerized NGINX configurations, and reporting all active NGINX traffic hijacking rules.Such findings come as 56% of React2Shell exploitation attempts two months after the flaw's disclosure were noted by GreyNoise to have stemmed from just a pair of IP addresses. While one of the IP addresses enables cryptomining binary retrieval from staging servers, the other facilitates direct reverse shell opening to the scanner IP, said GreyNoise researchers.
Threat Intelligence, Network Security
Illicit NGINX configurations harnessed for web traffic hijacking

An In-Depth Guide to Network Security
Get essential knowledge and practical strategies to fortify your network security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



