Bissa Scanner Used AI-Assisted Workflows to Exploit 900+ Targets and Harvest Credentials

Summary
DFIR Report researchers found an exposed server documenting Bissa Scanner’s large-scale React2Shell exploitation, credential harvesting, and victim-data collection, with Claude Code and OpenClaw supporting the operator’s workflow.
Key points
- Logs showed the operation scanned millions of targets and recorded more than 900 confirmed exploits of React2Shell (CVE-2025-55182).
- The scanner harvested .env files and other secrets, including credentials for AI, cloud, payment, messaging, and database services; more than 30,000 distinct .env filenames were found in archived data.
- The operator used Claude Code and OpenClaw to support scanner troubleshooting, orchestration, and collection workflow management.
- Recovered victim data included financial, payroll, HR, CRM, and other business-sensitive records; the researchers said initial access to two victim clusters could not be confirmed.
- The operation used Telegram bots for exploit alerts and Filebase S3-compatible storage to archive harvested files.
- The researchers reported coordinated disclosures and direct victim notifications, and said law enforcement had been engaged.
- Recommended defenses include patching internet-facing applications, moving credentials out of .env files, limiting credential scope, controlling egress, and rotating exposed secrets.
Article Details
- Attack Vectors
- Bissa scanner used a React2Shell exploitation workflow targeting internet-facing applications. Logs indicated more than 900 confirmed compromises.
- The operator harvested .env files and other secrets, then reviewed and validated access to prioritize valuable victim environments.
- Scripts batched harvested .env files into ZIP archives and uploaded them to an off-box Filebase bucket.
- A WordPress module checked for vulnerable W3 Total Cache versions, but the recovered module lacked an RCE payload and the researchers found no evidence of successful exploitation through it.
- Defensive Notes
- Patch internet-facing applications and frameworks promptly and monitor vendor advisories.
- Move production credentials out of .env files, limit their permissions and lifetimes, and use a secret manager.
- Harden cloud metadata access, restrict RBAC and service-account tokens, and avoid mounting container runtime sockets into application workloads.
- Route application-tier outbound traffic through a logged proxy; scan for embedded secrets and use canary tokens.
- Prepare credential-rotation procedures and rehearse response to a leaked production key.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| HOSTNAME | cs2[.]ip[.]thc[.]org | Host of ZIP target feeds obtained for the Bissa scanner exploitation workflow. |
MITRE ATT&CK
T1005 · Data from Local SystemThe operator collected victim .env files and, in some victim data clusters, business-sensitive records.T1190 · Exploit Public-Facing ApplicationThe scanner exploited internet-facing targets through CVE-2025-55182; logs indicated more than 900 confirmed compromises.T1552.001 · Credentials In FilesThe operation harvested credentials from tens of thousands of victim .env files.T1560 · Archive Collected DataScanner scripts batched harvested .env files into ZIP archives before uploading them.T1567.002 · Exfiltration to Cloud StorageThe scanner uploaded ZIP archives of harvested victim .env files to an off-box Filebase bucket.T1595.002 · Vulnerability ScanningThe React2Shell workflow scanned millions of internet-facing targets for exploitation.
CVE
CVE-2025-55182We identified a large-scale React2Shell (CVE-2025-55182) operation that scanned millions of targets and confirmed 900+ successful exploits.CVE-2025-9501The scanner also includes a dedicated WordPress module targeting CVE-2025-9501, an unauthenticated command injection in the W3 Total Cache plugin (versions prior to 2.8.13, CVSS 9.0).
People
Threat Actors
Vendors
Products
Next.jsOne of the most interesting findings was a Next.js React2Shell (CVE-2025-55182) exploitation workflow built around Bissa scanner which consisted of the following:ReactTelegramThe host also exposed Telegram-based alerting and command infrastructure tied to the broader Bissa scanner ecosystem, providing rare visibility into the operator’s notification workflow and public-facing handles.W3 Total CacheThe scanner also includes a dedicated WordPress module targeting CVE-2025-9501, an unauthenticated command injection in the W3 Total Cache plugin (versions prior to 2.8.13, CVSS 9.0).WordPressThe scanner also includes a dedicated WordPress module targeting CVE-2025-9501, an unauthenticated command injection in the W3 Total Cache plugin (versions prior to 2.8.13, CVSS 9.0).
Tools
Bissa scannerThe host also exposed Telegram-based alerting and command infrastructure tied to the broader Bissa scanner ecosystem, providing rare visibility into the operator’s notification workflow and public-facing handles.Claude CodeClaude Code and OpenClaw were used as an operator-side harness supporting exploitation activity and workflow orchestration.OpenClawClaude Code and OpenClaw were used as an operator-side harness supporting exploitation activity and workflow orchestration.
Industries
Cryptocurrencyfollow-on activity on organizations that met a clear value threshold, particularly in the financial, cryptocurrency, and retail sectors.financialand follow-on activity on organizations that met a clear value threshold, particularly in the financial, cryptocurrency, and retail sectors.Retailon organizations that met a clear value threshold, particularly in the financial, cryptocurrency, and retail sectors.