Start your day with intelligence. Get The OODA Daily Pulse.

Home > Briefs > Cyber > Google Sees 5 Chinese Groups Exploiting React2Shell for Malware Delivery

Google Sees 5 Chinese Groups Exploiting React2Shell for Malware Delivery

Multiple groups expand attacks using react2shell flaw.

Google says five additional China‑linked threat groups are exploiting the React2Shell vulnerability to deploy a range of malware. The flaw, disclosed on December 3, enables remote code execution in React 19 systems using Server Components and has been targeted since the day it became public. GTIG observed groups delivering tools such as Minocat, Snowlight, Compood, Hisonic, and Angryrebel.Linux, while noting that cybercriminals and Iran‑linked actors are also active. Three newer React vulnerabilities have since emerged, though two lead only to denial‑of‑service and one exposes source code.

Read more:

https://www.securityweek.com/google-sees-5-chinese-groups-exploiting-react2shell-for-malware-delivery/

Tagged: China Google malware