ZnDoor is a malware family that is currently exploiting the React2Shell vulnerability to compromise network devices.
ZnDoor is a malware family that is currently exploiting the React2Shell vulnerability to compromise network devices. The operators appear focused on breaching network infrastructure, indicating a campaign aimed at gaining footholds within enterprise networks. Its active exploitation highlights a notable risk to exposed network devices and their infrastructure.
In December 2025, Japanese organizations are facing attacks exploiting the React2Shell vulnerability (CVE-2025-55182) in React/.js applications. Initially used for cryptocurrency mining, the ZnDoor malware has evolved…