{"id":332443,"date":"2025-12-05T17:55:10","date_gmt":"2025-12-05T17:55:10","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/332443\/"},"modified":"2025-12-05T17:55:10","modified_gmt":"2025-12-05T17:55:10","slug":"chinese-hackers-have-started-exploiting-the-newly-disclosed-react2shell-vulnerability","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/332443\/","title":{"rendered":"Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability"},"content":{"rendered":"<p>\ue802Dec 05, 2025\ue804Ravie LakshmananVulnerability \/ Software Security<\/p>\n<p><a href=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2025\/12\/React2Shell.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2025\/12\/React2Shell.jpg\" alt=\"\" border=\"0\" data-original-height=\"470\" data-original-width=\"900\"\/><\/a><\/p>\n<p>Two hacking groups with ties to China have been observed weaponizing the newly disclosed security flaw in React Server Components (RSC) within hours of it becoming public knowledge.<\/p>\n<p>The vulnerability in question is <a href=\"https:\/\/thehackernews.com\/2025\/12\/critical-rsc-bugs-in-react-and-nextjs.html\" rel=\"noopener nofollow\" target=\"_blank\">CVE-2025-55182<\/a> (CVSS score: 10.0), aka <a href=\"https:\/\/research.jfrog.com\/post\/react2shell\/\" rel=\"noopener nofollow\" target=\"_blank\">React2Shell<\/a>, which allows <a href=\"https:\/\/unit42.paloaltonetworks.com\/cve-2025-55182-react-and-CVE-2025-66478-next\/\" rel=\"noopener nofollow\" target=\"_blank\">unauthenticated remote code execution<\/a>. It has been addressed in React versions 19.0.1, 19.1.2, and 19.2.1.<\/p>\n<p>According to a new report shared by Amazon Web Services (AWS), two China-linked threat actors known as Earth Lamia and Jackpot Panda have been observed attempting to exploit the maximum-severity security flaw.<\/p>\n<p>&#8220;Our analysis of exploitation attempts in AWS MadPot honeypot infrastructure has identified exploitation activity from IP addresses and infrastructure historically linked to known China state-nexus threat actors,&#8221; CJ Moses, CISO of Amazon Integrated Security, <a href=\"https:\/\/aws.amazon.com\/blogs\/security\/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182\/\" rel=\"noopener nofollow\" target=\"_blank\">said<\/a> in a report shared with The Hacker News.<\/p>\n<p><a href=\"https:\/\/thehackernews.uk\/ransomware_dragon_d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2025\/12\/ransomware_dragon_d.png\" width=\"729\" height=\"91\"\/><\/a><\/p>\n<p>Specifically, the tech giant said it identified infrastructure associated with <a href=\"https:\/\/thehackernews.com\/2025\/05\/china-linked-hackers-exploit-sap-and.html\" rel=\"noopener nofollow\" target=\"_blank\">Earth Lamia<\/a>, a China-nexus group that was attributed to attacks exploiting a critical SAP NetWeaver flaw (CVE-2025-31324) earlier this year.<\/p>\n<p>The hacking crew has targeted sectors across financial services, logistics, retail, IT companies, universities, and government organizations across Latin America, the Middle East, and Southeast Asia.<\/p>\n<p>The attack efforts have also originated from infrastructure related to another China-nexus cyber threat actor known as <a href=\"https:\/\/www.crowdstrike.com\/adversaries\/jackpot-panda\/\" rel=\"noopener nofollow\" target=\"_blank\">Jackpot Panda<\/a>, which has primarily singled out entities that are either engaged in or support online gambling operations in East and Southeast Asia.<\/p>\n<p>Jackpot Panda, per CrowdStrike, is assessed to be active since at least 2020, and has targeted trusted third-party relationships in an attempt to deploy malicious implants and gain initial access. Notably, the threat actor was <a href=\"https:\/\/thehackernews.com\/2022\/10\/comm100-chat-provider-hijacked-to.html\" rel=\"noopener nofollow\" target=\"_blank\">connected<\/a> to the supply chain compromise of a chat app known as <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/22\/l\/probing-weaponized-chat-applications-abused-in-supply-chain-atta.html\" rel=\"noopener nofollow\" target=\"_blank\">Comm100<\/a> in September 2022. The activity is tracked by ESET as <a href=\"https:\/\/thehackernews.com\/2023\/05\/operation-chattygoblin-hackers.html\" rel=\"noopener nofollow\" target=\"_blank\">Operation ChattyGoblin<\/a>.<\/p>\n<p>It has since emerged that a Chinese hacking contractor, I-Soon, may have been <a href=\"https:\/\/thehackernews.com\/2024\/03\/two-chinese-apt-groups-ramp-up-cyber.html\" rel=\"noopener nofollow\" target=\"_blank\">involved<\/a> in the <a href=\"https:\/\/www.huntandhackett.com\/blog\/isoon-leak-sheds-light\" rel=\"noopener nofollow\" target=\"_blank\">supply chain attack<\/a>, citing <a href=\"https:\/\/blog.bushidotoken.net\/2024\/02\/lessons-from-isoon-leaks.html\" rel=\"noopener nofollow\" target=\"_blank\">infrastructure overlaps<\/a>. Interestingly, attacks mounted by the group in 2023 have primarily focused on Chinese-speaking victims, indicating possible domestic surveillance.<\/p>\n<p>&#8220;Beginning in May 2023, the adversary used a trojanized installer for CloudChat, a China-based chat application popular with illegal, Chinese-speaking gambling communities in Mainland China,&#8221; CrowdStrike said in its Global Threat Report released last year.<\/p>\n<p><a href=\"https:\/\/thehackernews.uk\/zscaler-ai-event-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2025\/12\/zz-d.png\" width=\"729\" height=\"91\"\/><\/a><\/p>\n<p>&#8220;The trojanized installer served from CloudChat&#8217;s website contained the first stage of a multi-step process that ultimately deployed XShade \u2013 a novel implant with code that overlaps with Jackpot Panda&#8217;s unique CplRAT implant.&#8221;<\/p>\n<p>Amazon said it also detected threat actors exploiting 2025-55182 along with other N-day flaws, including a vulnerability in NUUO Camera (<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-1338\" rel=\"noopener nofollow\" target=\"_blank\">CVE-2025-1338<\/a>, CVSS score: 7.3), suggesting broader attempts to scan the internet for unpatched systems.<\/p>\n<p>The observed activity involves attempts to run discovery commands (e.g., whoami), write files (&#8220;\/tmp\/pwned.txt&#8221;), and read files containing sensitive information (e.g., &#8220;\/etc\/passwd&#8221;).<\/p>\n<p>&#8220;This demonstrates a systematic approach: threat actors monitor for new vulnerability disclosures, rapidly integrate public exploits into their scanning infrastructure, and conduct broad campaigns across multiple Common Vulnerabilities and Exposures (CVEs) simultaneously to maximize their chances of finding vulnerable targets,&#8221; Moses said.<\/p>\n<p>Cloudflare Blames Outage on React2Shell Patch<\/p>\n<p>The development comes as Cloudflare experienced a brief but widespread outage that caused websites and online platforms to return a &#8220;500 Internal Server Error&#8221; message.<\/p>\n<p>&#8220;A change made to how Cloudflare&#8217;s Web Application Firewall parses requests caused Cloudflare&#8217;s network to be unavailable for several minutes this morning,&#8221; the web infrastructure provider <a href=\"https:\/\/www.cloudflarestatus.com\/incidents\/lfrm31y6sw9q\" rel=\"noopener nofollow\" target=\"_blank\">said<\/a> in a statement Friday. &#8220;This was not an attack; the change was deployed by our team to help mitigate the industry-wide vulnerability disclosed this week in React Server Components.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"\ue802Dec 05, 2025\ue804Ravie LakshmananVulnerability \/ Software Security Two hacking groups with ties to China have been observed weaponizing&hellip;\n","protected":false},"author":2,"featured_media":332444,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[28,5407,5400,5393,5392,5394,5395,5396,5401,5397,5398,5403,5405,5404,5402,5399,5406],"class_list":["post-332443","post","type-post","status-publish","format-standard","has-post-thumbnail","category-business","tag-business","tag-computer-security","tag-cyber-attacks","tag-cyber-news","tag-cyber-security-news","tag-cyber-security-news-today","tag-cyber-security-updates","tag-cyber-updates","tag-data-breach","tag-hacker-news","tag-hacking-news","tag-how-to-hack","tag-information-security","tag-network-security","tag-ransomware-malware","tag-software-vulnerability","tag-the-hacker-news"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/332443","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=332443"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/332443\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/332444"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=332443"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=332443"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=332443"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}