Vulnerability Management, Patch/Configuration Management

Over 30 organizations impacted by sweeping React2Shell exploitation

Hacker attack computer hardware microchip while process data through internet network, 3d rendering insecure Cyber Security exploit database breach concept, virus malware unlock warning screen

Attacks involving the critical React2Shell remote code execution vulnerability, tracked as CVE-2025-55182, were noted by Palo Alto Networks Unit 42 researchers to have compromised more than 30 organizations in various industries, reports BleepingComputer.

Chinese state-backed threat operation UNC5174, also known as CL-STA-1015, has been behind some of the intrusions leveraging the flaw, which have facilitated the deployment of the Snowlight malware dropper and the Vshell backdoor for remote access and lateral movement, according to Unit 42 researchers.

Data from the Shadowserver Foundation revealed that React2Shell intrusions could affect 77,664 IP addresses worldwide, with the U.S. accounting for almost 23,700 of the addresses. Most of the traffic attempting to abuse the bug seemed to be automated, mainly originating from the Netherlands, China, and the U.S., reported GreyNoise, which noted that intrusions led to Cobalt Strike beacon delivery. Such a development comes after Cloudflare linked an outage to an update it had issued to address the React issue.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds