ZnDoor Malware Targets React2Shell Vulnerability in Japanese Networks
First seen 15 Dec 2025, 20:51 UTC
•
•91% similarity
•36
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
In December 2025, Japanese organizations are facing attacks exploiting the React2Shell vulnerability (CVE-2025-55182) in React/.js applications. Initially used for cryptocurrency mining, the ZnDoor malware has evolved to compromise network infrastructure. Security researchers are actively investigating these sophisticated threats.
ThreatCluster AI
How this analysis works