Analyzing React2Shell Threat Actors
By Adam Metcalfe-Pearce
1/16/2026
https://www.f5.com/labs/articles/analyzing-react2shell-threat-actors
| Notes |
|---|
| CVE-2025-55182 |
| React2Shell |
| PHPUnit |
| RCE |
| React |
| React Server Components |
| Unsafe Deserialization |
| deserialization |
| CVE-2023-1389 |
| TP-Link Archer AX21 |
| command injection |
| CVE-2019-9082 |
| ThinkPHP |
| PHP injection |
| CVE-2024-4577 |
| Apache PHP-CGI |
| argument injection |
| CVSS |
| React.js |
| robots.txt – ismyhero >>public/robots.txt |
| RondoDox botnet https://www.f5.com/labs/articles/shellshock-makes-a-comeback-and-rondodox-changes-tactics |
| https://www.f5.com/labs/articles/tracking-rondodox-malware-exploiting-many-iot-vulnerabilities |
| wget busybox curl |
| curl to sh |
| rondo.aqu.sh rondo2012@atomicmail.io |
| IoC |
| ReactOnMynuts |
| React Server: execSync |
| chmod 777 |
| stdout |
| x86 |
| binary in /dev |
| root user |
| ivk.sh |
| nxtgrab.php |
| .aws/credentials |
| AWS |
| Linux |
| Node |
| Node hxxp module |
| DNS |
| HTTP GET |
| HTTP POST |
| process telemetry |
| netcat |
| 45.125.66.90:3443 |
| telnet |
| mewo.oceanic-node[.]su |
| ping command |
| ICMP echo |
| ICMP |
| RTT |
| TTL |
| CAP_NET_RAW |
| reverse shell |
| /tmp/f |
| FIFO |
| mkfifo reverse shell |
| User-Agent |
| fileless malware |