Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

ZnDoor Malware Exploiting React2Shell Vulnerability to Compromise Network Devices

As of December 2025, a critical vulnerability in React/Next.js applications, identified as CVE-2025-55182 and known as React2Shell, has been increasingly exploited across Japanese organizations.

As of December 2025, a critical vulnerability in React/Next.js applications, identified as CVE-2025-55182 and known as React2Shell, has been increasingly exploited across Japanese organizations.

This vulnerability facilitates remote code execution and has initially been used to deploy cryptocurrency miners . However, security researchers have identified a more advanced threat targeting network infrastructure with a malware known as ZnDoor.

ZnDoor, a remote access trojan, exhibits complex functionalities that surpass simple mining operations. Evidence suggests its activity dates back to at least December 2023, indicating a strategic deployment in targeted environments.

The malware's architecture suggests deliberate development aimed at compromising network devices, posing a significant risk to enterprise security teams.

NTT Security analysts have identified ZnDoor through comprehensive forensic analysis of affected systems.

This vulnerability facilitates remote code execution and has initially been used to deploy cryptocurrency miners .
Stephen Gale · Thehackingpost

Infection Mechanism and Command and Control Operations

The infection process begins with exploiting the React2Shell vulnerability to execute a shell command. This command downloads and runs ZnDoor from external servers located at 45.76.155.14.

The malware then communicates with its command and control server at api.qtss.cc:443. Configuration details, including the C2 address and port, are encrypted using AES-CBC encryption after Base64 decoding, safeguarding its communication infrastructure.

ZnDoor functions as a fully equipped remote access trojan with extensive system control capabilities. It continuously communicates with its C2 server, transmitting system information such as network addresses, hostname, username, and process identifiers via HTTP POST requests.

This ongoing communication allows attackers to execute commands for file operations, shell execution, system enumeration, and SOCKS5 proxy activation.

Advertisement

The command structure uses double-hash delimiters to parse instructions, enabling operations like interactive shell spawning, directory listing, file manipulation, and network tunneling .

ZnDoor employs multiple evasion techniques, such as process name spoofing to mimic legitimate system processes, complicating detection through standard monitoring methods.

Additionally, it alters file timestamps to January 15, 2016, to avoid forensic investigations. The malware also implements self-restart mechanisms using child processes, further hindering analysis efforts. These evasion tactics underscore the advanced nature of this threat, emphasizing the need for behavioral monitoring.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories