PeerBlight Linux Backdoor Exploits React2Shell CVE-2025-55182

Huntress is seeing threat actors exploit React2Shell (CVE-2025-55182) to deploy a Linux backdoor, a reverse proxy tunnel, and a Go-based post-exploitation implant.

security

Sources

Vulnerabilities

Why this score
Signals contributing to the severity score
SignalPoints
kev added50
kev short fuse — 7 days to remediate15
kev ransomware10
public poc — 458 repositories20