analyzing_react2shell-metcalfe-Pearce2026

2026-08-30

Analyzing React2Shell Threat Actors

By Adam Metcalfe-Pearce

1/16/2026

https://www.f5.com/labs/articles/analyzing-react2shell-threat-actors

Notes
CVE-2025-55182
React2Shell
PHPUnit
RCE
React
React Server Components
Unsafe Deserialization
deserialization
CVE-2023-1389
TP-Link Archer AX21
command injection
CVE-2019-9082
ThinkPHP
PHP injection
CVE-2024-4577
Apache PHP-CGI
argument injection
CVSS
React.js
robots.txt – ismyhero >>public/robots.txt
RondoDox botnet https://www.f5.com/labs/articles/shellshock-makes-a-comeback-and-rondodox-changes-tactics
https://www.f5.com/labs/articles/tracking-rondodox-malware-exploiting-many-iot-vulnerabilities
wget busybox curl
curl to sh
rondo.aqu.sh rondo2012@atomicmail.io
IoC
ReactOnMynuts
React Server: execSync
chmod 777
stdout
x86
binary in /dev
root user
ivk.sh
nxtgrab.php
.aws/credentials
AWS
Linux
Node
Node hxxp module
DNS
HTTP GET
HTTP POST
process telemetry
netcat
45.125.66.90:3443
telnet
mewo.oceanic-node[.]su
ping command
ICMP echo
ICMP
RTT
TTL
CAP_NET_RAW
reverse shell
/tmp/f
FIFO
mkfifo reverse shell
User-Agent
fileless malware

Links to this note