An exposed server revealed a large-scale operation that used the Bissa scanner platform, Claude Code and OpenClaw to automate exploitation of internet‑facing targets via a React2Shell vulnerability (CVE‑2025‑55182). The campaign harvested millions of .env files containing high‑value credentials from AI, cloud, payment and messaging services. Collected data were uploaded to a public S3 bucket on Filebase for further use. The operation targeted organizations in financial, cryptocurrency and retail sectors.
Analysts recovered over 13,000 files showing the workflow for scanning, exploiting, validating and prioritising victim environments. Logs confirmed more than 900 successful compromises using the React2Shell exploit. Telegram bots were used for real‑time alerting, linking each hit to victim details. The scanner also contained a module for a WordPress W3 Total Cache vulnerability (CVE‑2025‑9501) though no successful exploitation was observed.
Patch vulnerable applications and frameworks promptly, especially the React2Shell and WordPress W3 Total Cache components. Move secrets out of .env files into dedicated secret managers and rotate credentials regularly. Harden cloud metadata access and enforce least‑privilege RBAC. Monitor outbound traffic to detect unauthorized uploads to external storage services.
Implement detection rules for exploitation of CVE‑2025‑55182 and unauthorized S3 uploads. Block known malicious domains and Telegram bot communications. Conduct forensic analysis of compromised hosts to locate residual payloads and remove them. Notify affected users and rotate any leaked credentials immediately.
Prerequisite: The Telemetry & Baseline Pre‑flight Check must have passed.
Attack Narrative & Commands: The adversary has harvested a set of confidential documents from /var/secret/ . To avoid detection, they first archive the data into a password‑protected ZIP file, then use curl to upload the archive directly to the Filebase S3 endpoint through the corporate forward proxy. The proxy logs the full request URL, which matches the detection rule.
Regression Test Script:
Join SOC Prime's Detection as Code platform to improve visibility into threats most relevant to your business. To help you get started and drive immediate value, book a meeting now with SOC Prime experts.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
