005
ID: e9df8bb7-2ffd-4296-b44d-c9eaa011d3fd
STIX ID: report--e9df8bb7-2ffd-4296-b44d-c9eaa011d3fd
Threat Score
78/100
Uploaded: 2026-05-14
Published Date: 2026-05-14
Last Modified Date: 2026-05-14
Created by: Thesis Research
TLP:GREEN
...
...
Datadog Security Labs reported an active campaign leveraging the critical React2Shell vulnerability to modify NGINX configurations (including via Baota/BT panels) and proxy legitimate web traffic through attacker-controlled backends. The attackers use a multi-stage shell-script toolkit (zx.sh, bt.sh, 4zdh.sh, zdh.sh, ok.sh) for discovery, persistence, and rule generation; they target Asian TLDs, government/education domains, and Chinese hosting panels. GreyNoise telemetry links large-scale exploitation activity to over 1,000 unique source IPs and highlights two IPs responsible for the majority of observed attempts, with post-exploitation payloads ranging from cryptomining to interactive reverse shells.
