---
title: "Threat Intel Content Update: 12/17/2025"
description: Tidal Cyber's Threat Intelligence Content updates for the week of 12/17/25 - Substantial updates to current React2Shell Exploitation Campaign
---

[Threat Intelligence Content Updates ](https://www.tidalcyber.com/threat-updates)

# [Threat Intel Content Update: 12/17/2025](https://www.tidalcyber.com/threat-updates/threat-intel-content-update-12/17/2025)

 Written by [Tidal Cyber](https://www.tidalcyber.com/threat-updates/author/tidal-cyber) | Dec 18, 2025 4:00:01 PM

We made substantial updates to our Campaign object focused on the [React2Shell exploit campaign](https://app.tidalcyber.com/campaigns/fcba5560-af79-4a3e-828d-135e0be160d7) (CVE-2025-55182 & CVE-2025-66478), including nine Techniques and dozens of new Procedures. **Forty discrete named Groups and Software have been linked to these exploits so far**, an unusually high number, underscoring actors’ intense appetite to abuse this critical vulnerability.

And among many other updates:

- Group & tool updates from [CISA’s latest advisory](https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-343a) on pro-Russian hacktivists opportunistically targeting U.S. and global critical infrastructure.
- [Content](https://app.tidalcyber.com/campaigns/718cb1fb-82c9-4f52-857b-5dec2df829b9?tab=2) related to a reported shift by the initial access entity Storm-0249 from mass phishing to more targeted access operations
- Another new [Campaign](https://app.tidalcyber.com/campaigns/99cb11cf-cb9a-41ae-835e-c9aee98f7c8b?tab=2) possibly tied to the Void Rabisu/RomCom backdoor entity (highlighted in last week’s update)
- Key new [malware object](https://app.tidalcyber.com/software/40fbdaf6-6df7-42e0-9a87-e1dbb0d635e1?tab=4) plus several others linked to recently reported CastleLoader malware-as-a-service activity, which impacted several industries

#### **12/17/25: New Objects – Spotlight Procedures**

- **PS1031876: Installation and Use of Interactive Web Shell Masquerading as React File Manager**

- **PS1031839: Download and Execute Remote Shell Scripts via curl/wget and bash**

- **PS1031864: Exploit CVE-2025-55182 for Unauthenticated Remote Code Execution** 
    - Sightings from various recently processed threat reports, which document the key remote code execution and malware payload ingress activity associated with the React2Shell exploit campaign.

> **Threat-Led Defense commentary**: This campaign has featured an usually high volume of discrete actors deploying various payloads after exploiting the vulnerabilities. The vulnerabilities’ prevalence and relative ease of exploit have likely attracted increased actor interest. Tracking Sightings associated with observed payloads gives defenders opportunities to ensure they have defensive coverage aligned with precise early post-exploit behavior.

 

[View full post](https://www.tidalcyber.com/threat-updates/threat-intel-content-update-12/17/2025)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Tidal Cyber"
  },
  "dateModified" : "2025-12-18T16:00:01.532Z",
  "datePublished" : "2025-12-18T16:00:01Z",
  "headline" : "Threat Intel Content Update: 12/17/2025",
  "image" : {
    "@type" : "ImageObject",
    "height" : 1667,
    "url" : "https://21164103.fs1.hubspotusercontent-na1.net/hubfs/21164103/Threat%20Intel%201217.jpg",
    "width" : 3000
  },
  "mainEntityOfPage" : "https://www.tidalcyber.com/threat-updates/threat-intel-content-update-12/17/2025",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "Threat Intelligence Content Updates"
  }
}
```