Bissa Scanner Used AI-Assisted Workflows to Exploit 900+ Targets and Harvest Credentials

· Original article ↗

Summary

DFIR Report researchers found an exposed server documenting Bissa Scanner’s large-scale React2Shell exploitation, credential harvesting, and victim-data collection, with Claude Code and OpenClaw supporting the operator’s workflow.

Key points

  • Logs showed the operation scanned millions of targets and recorded more than 900 confirmed exploits of React2Shell (CVE-2025-55182).
  • The scanner harvested .env files and other secrets, including credentials for AI, cloud, payment, messaging, and database services; more than 30,000 distinct .env filenames were found in archived data.
  • The operator used Claude Code and OpenClaw to support scanner troubleshooting, orchestration, and collection workflow management.
  • Recovered victim data included financial, payroll, HR, CRM, and other business-sensitive records; the researchers said initial access to two victim clusters could not be confirmed.
  • The operation used Telegram bots for exploit alerts and Filebase S3-compatible storage to archive harvested files.
  • The researchers reported coordinated disclosures and direct victim notifications, and said law enforcement had been engaged.
  • Recommended defenses include patching internet-facing applications, moving credentials out of .env files, limiting credential scope, controlling egress, and rotating exposed secrets.

Article Details

Attack Vectors
  • Bissa scanner used a React2Shell exploitation workflow targeting internet-facing applications. Logs indicated more than 900 confirmed compromises.
  • The operator harvested .env files and other secrets, then reviewed and validated access to prioritize valuable victim environments.
  • Scripts batched harvested .env files into ZIP archives and uploaded them to an off-box Filebase bucket.
  • A WordPress module checked for vulnerable W3 Total Cache versions, but the recovered module lacked an RCE payload and the researchers found no evidence of successful exploitation through it.
Defensive Notes
  • Patch internet-facing applications and frameworks promptly and monitor vendor advisories.
  • Move production credentials out of .env files, limit their permissions and lifetimes, and use a secret manager.
  • Harden cloud metadata access, restrict RBAC and service-account tokens, and avoid mounting container runtime sockets into application workloads.
  • Route application-tier outbound traffic through a logged proxy; scan for embedded secrets and use canary tokens.
  • Prepare credential-rotation procedures and rehearse response to a leaked production key.

Indicators of compromise

TypeIndicatorContext
HOSTNAMEcs2[.]ip[.]thc[.]orgHost of ZIP target feeds obtained for the Bissa scanner exploitation workflow.

MITRE ATT&CK

CVE

People

Threat Actors

Vendors

Products

Tools

Industries

Related Articles