216.73.217.174

AI/LLM-Generated Malware Used to Exploit React2Shell

· Published 10/02/2026 17:46 · Modified 11/02/2026 10:05

Export JSON

Essential information

Published
10/02/2026 17:46
Modified
11/02/2026 10:05
Tags
2026-02-10 CVE-2025-55182 ai-generated malware crypto mining llm react2shell xmrig
Related entities
1 vulnerabilities (cve), 3 observables, 14 techniques (mitre), 1 malware, 1 others

Description

Darktrace identified an sample exploiting the vulnerability in its honeypot environment. The incident demonstrates how -assisted development enables low-skill attackers to rapidly create effective exploitation tools. The attack chain involved spawning a container named 'python-metrics-collector' on an exposed Docker daemon, downloading and executing a Python script, and deploying a crypto miner. The malware sample featured thorough code documentation and lacked typical obfuscation, indicating AI generation. This highlights the growing trend of AI-enabled cyber threats that are now operational and accessible to anyone, posing new challenges for defenders.

External references