Listen to this Post

A new wave of cyberattacks is targeting NGINX web servers and management panels like Baota (BT), raising alarms across Asia and critical sectors worldwide. Researchers have uncovered an active campaign in which attackers manipulate NGINX configurations to hijack legitimate web traffic and route it through infrastructure under their control. The operation is sophisticated, leveraging the recent high-severity React2Shell vulnerability (CVE-2025-55182, CVSS 10.0) to establish persistent access and control over affected servers.
Overview of the Attack Campaign
Datadog Security Labs reported that threat actors are exploiting NGINX servers, especially in Asian domains (.in, .id, .pe, .bd, .th), Chinese hosting platforms like Baota Panel, and government or educational TLDs (.gov, .edu). Once exploited, malicious configurations intercept user requests and reroute them to attacker-controlled servers, enabling traffic monitoring, credential theft, or further compromise. Security researcher Ryan Simon emphasized that the attack leverages shell scripts to implant these configurations in a multi-stage approach.
Multi-Stage Toolkit and Attack Workflow
The attackers rely on a toolkit consisting of several scripts:
zx.sh – Orchestrates subsequent stages using tools like curl or wget; falls back to raw TCP connections if blocked.
bt.sh – Targets Baota Panels to overwrite NGINX configurations.
4zdh.sh – Identifies NGINX configuration locations and minimizes errors during injection.
zdh.sh – Focuses on Linux and containerized NGINX installations, especially Asian TLDs.
ok.sh – Generates reports on active hijacking rules.
These scripts ensure persistence, automatic configuration injection, and redirection of web traffic, showing the attackers’ deep familiarity with NGINX internals.
Exploitation Patterns and Infrastructure
GreyNoise reports show that just two IP addresses, 193.142.147[.]209 and 87.121.84[.]24, account for 56% of observed exploitation attempts post-React2Shell disclosure. Between January 26 and February 2, 2026, over 1,000 unique IP addresses participated in these attacks. Payloads vary: one deploys cryptomining binaries, while the other establishes reverse shells, indicating a preference for interactive access over automated resource theft.
Coordinated Reconnaissance Campaigns
The web traffic hijacking campaign parallels recent reconnaissance efforts against Citrix ADC and Netscaler Gateway infrastructure. Threat actors used tens of thousands of residential proxies and a single Azure-hosted IP to discover login panels and enumerate software versions. GreyNoise noted the campaign operated in dual modes: wide-scale login panel discovery through proxy rotation, and concentrated version detection via a centralized cloud IP. These coordinated tactics point to careful planning and long-term attack objectives.
What Undercode Says:
Sophistication of Multi-Stage Toolkits
The attack demonstrates an alarming level of sophistication. By splitting functionality across multiple scripts, attackers ensure both redundancy and stealth. Even if one script is detected, others maintain the ability to persist and redirect traffic. This modular approach mirrors advanced persistent threat (APT) tactics typically seen in state-sponsored operations.
Target Selection Reflects Geopolitical Focus
The focus on Asian TLDs, Chinese hosting infrastructure, and government/educational domains is telling. It suggests that the attackers are not just conducting opportunistic attacks but have specific geopolitical or intelligence-driven objectives. The inclusion of containerized Linux targets highlights the increasing prevalence of modern deployment environments in cyber espionage.
Implications for Traffic Integrity and Data Theft
Hijacking legitimate web traffic is particularly dangerous because it allows attackers to silently exfiltrate sensitive data. Users and organizations may remain unaware their connections are compromised, increasing the risk of credential theft, intellectual property exposure, and injection of malicious content.
React2Shell Exploitation Trend
The fact that two IPs dominate exploitation attempts suggests centralized control of payload distribution. This points to organized campaigns rather than fragmented attacks by opportunistic actors, increasing the potential for high-impact damage.
Need for Real-Time Monitoring and Patch Management
Organizations must prioritize patching React2Shell vulnerabilities and deploying continuous monitoring for unauthorized NGINX configuration changes. Automated alerts and integrity checks can mitigate long-term persistence and reduce the window of exploitation.
Convergence with Broader Reconnaissance Campaigns
The concurrent reconnaissance activity against Citrix and Netscaler gateways indicates that attackers are preparing for multi-vector operations. The dual-mode strategy—wide-scale panel discovery and targeted cloud-based enumeration—reveals an intent to scale future attacks efficiently while maintaining operational secrecy.
Long-Term Risk Assessment
This campaign signals a shift in attacker behavior toward combining web traffic hijacking with cryptomining and reverse shell operations. Such hybrid objectives increase both financial and strategic risks for targeted organizations, emphasizing the need for proactive cybersecurity measures.
🔍 Fact Checker Results:
✅ Verified: React2Shell CVE-2025-55182 is a critical NGINX vulnerability.
✅ Verified: Baota Panel has been previously targeted for configuration exploits.
❌ Misinformation: No evidence suggests attackers have compromised U.S.-based educational TLDs en masse—focus remains on Asian and select government/edu TLDs.
📊 Prediction
The campaign is likely to escalate in both scope and sophistication over the next six months. Threat actors may expand beyond Asian TLDs to additional global targets, potentially integrating AI-driven reconnaissance and automated traffic hijacking tools. Organizations running NGINX, especially in government, education, and high-value hosting sectors, must anticipate multi-vector exploitation attempts combining traffic interception, reverse shells, and cryptomining payloads. Enhanced monitoring, automated patching, and proactive threat intelligence sharing will be crucial in mitigating the next phase of attacks.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: thehackernews.com
Extra Source Hub (Possible Sources for article):
https://www.facebook.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




