PeerBlight Linux Backdoor Exploits React2Shell CVE-2025-55182
A critical vulnerability in React Server Components (CVE-2025-55182) is being exploited across various organizations. Attackers are deploying cryptominer malware, a Linux backdoor called PeerBlight, a reverse proxy tunnel named CowTunnel, and a Go-based post-exploitation implant dubbed ZinFoq. PeerBlight uses the BitTorrent DHT network as a fallback C2 mechanism. CowTunnel initiates outbound connections to attacker-controlled FRP servers. ZinFoq implements interactive shells, SOCKS5 proxying, and timestomping capabilities. A Kaiji botnet variant is also being distributed. The exploitation attempts target multiple industries and use automated tools. Immediate patching is recommended due to the ease of exploitation.
Pulse ID: 69398505e9eef97b07197db2
Pulse Link: https://otx.alienvault.com/pulse/69398505e9eef97b07197db2
Pulse Author: AlienVault
Created: 2025-12-10 14:34:45
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CryptoMiner #CyberSecurity #InfoSec #Linux #Malware #OTX #OpenThreatExchange #Proxy #ReverseProxy #Troll #Vulnerability #bot #botnet #socks5 #AlienVault