logo

005

ID: e9df8bb7-2ffd-4296-b44d-c9eaa011d3fd

STIX ID: report--e9df8bb7-2ffd-4296-b44d-c9eaa011d3fd

Threat Score

78/100

Uploaded: 2026-05-14

Published Date: 2026-05-14

Last Modified Date: 2026-05-14

Created by: Thesis Research

TLP:GREEN
...
...
Datadog Security Labs reported an active campaign leveraging the critical React2Shell vulnerability to modify NGINX configurations (including via Baota/BT panels) and proxy legitimate web traffic through attacker-controlled backends. The attackers use a multi-stage shell-script toolkit (zx.sh, bt.sh, 4zdh.sh, zdh.sh, ok.sh) for discovery, persistence, and rule generation; they target Asian TLDs, government/education domains, and Chinese hosting panels. GreyNoise telemetry links large-scale exploitation activity to over 1,000 unique source IPs and highlights two IPs responsible for the majority of observed attempts, with post-exploitation payloads ranging from cryptomining to interactive reverse shells.