top of page



Perceptive Security
SOC/SIEM Consultancy

North Korea-linked Actors Exploit React2Shell to Deploy New EtherRAT Malware
Published:
9 december 2025 om 18:25:00
Alert date:
9 december 2025 om 20:01:36
Source:
thehackernews.com
North Korea-linked threat actors are exploiting the React2Shell vulnerability in React Server Components to deploy EtherRAT malware. EtherRAT is a new remote access trojan that uses Ethereum smart contracts for command-and-control communications and implements five different Linux persistence mechanisms. This represents active exploitation of a critical security flaw by state-sponsored actors.
Technical details
Mitigation steps:
Affected products:
React Server Components
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
bottom of page
