Hackers Exploit React2Shell Vulnerability to Hijack NGINX Web Traffic
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Cybersecurity researchers have disclosed an active campaign that hijacks web traffic by exploiting the React2Shell vulnerability (CVE-2025-55182), which has a CVSS score of 10.0. The attack primarily targets NGINX installations and management panels like Baota (BT), aiming to reroute legitimate traffic through the attackers’ infrastructure. This activity was observed between January 26 and February 2, 2026, with a total of 1,083 unique source IP addresses involved in the exploitation.
The attackers utilize malicious NGINX configurations that intercept web traffic and redirect it using the ‘proxy_pass’ directive. The campaign focuses on Asian TLDs such as .in, .id, and .th, as well as government and educational domains like .edu and .gov. The exploitation is facilitated by a multi-stage toolkit that includes various shell scripts designed for persistence and the creation of malicious configuration files.
Details of the Malicious Toolkit
The toolkit comprises several scripts, including:
- zx.sh, which orchestrates subsequent stages using utilities like curl or wget.
- bt.sh, which targets the Baota (BT) Management Panel to overwrite NGINX configuration files.
- 4zdh.sh, which enumerates common NGINX configuration locations to minimize errors.
- zdh.sh, which focuses on Linux or containerized NGINX configurations and specific TLDs.
- ok.sh, which generates reports on active NGINX traffic hijacking rules.
GreyNoise has reported that two IP addresses, 193.142.147[.]209 and 87.121.84[.]24, are responsible for 56% of the exploitation attempts observed. These sources deploy distinct payloads, including cryptomining binaries and reverse shells, indicating a preference for interactive access rather than automated extraction.
This campaign follows a reconnaissance operation targeting Citrix ADC Gateway and Netscaler Gateway infrastructure, using residential proxies to discover login panels. The coordinated efforts reveal an evolving landscape of cyber threats that organizations must navigate.
Key Takeaways
- Regularly review and update NGINX configurations to prevent unauthorized changes.
- Monitor web traffic for unusual patterns that may indicate hijacking attempts.
- Implement security measures to protect management panels like Baota from exploitation.
- Stay informed about vulnerabilities like React2Shell and apply patches promptly.
- Consider using intrusion detection systems to identify and respond to suspicious activities.
Key Terms & Concepts
- React2Shell: In this article, React2Shell refers to a critical vulnerability (CVE-2025-55182) that allows attackers to hijack web traffic.
- NGINX: NGINX is an open-source web server and reverse proxy used for managing web traffic.
- proxy_pass: In this context, proxy_pass is a directive in NGINX configurations that redirects incoming requests to another server.
- CVE: CVE stands for Common Vulnerabilities and Exposures, a system for identifying and cataloging publicly known cybersecurity vulnerabilities.
- TLD: TLD stands for top-level domain, the last segment of a domain name, such as .com or .edu.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.