Skip to content
LATEST NEWS
 2026-05-16 NCA Launches New 12 Most Wanted Fugitives Appeal  2026-05-16 CISA Flags Cisco SD-WAN CVE-2026-20182 Exploits  2026-05-13 German DreamMarket Suspect Charged by US DOJ  2026-05-13 NCA Seizes £53K Linked to Mobster Whitey Bulger  2026-05-13 BlackOps Market Review

DarkDotWeb

  • ARTICLES
    • ABUSE
    • CRIME
    • CRYPTO CURRENCIES
    • DARKNET
    • DRUG LORDS
    • DRUGS
    • HARM-REDUCTION
    • INTERVIEWS
    • LAW ENFORCEMENT
    • MARKET SEIZURES
    • REVIEWS
    • SECURITY
    • TUTORIALS
    • WEAPONS
  • Harm Reduction
  • Darknet Markets
  • VENDOR SHOPS
  • Cool Links
  • DONATE TO US
  • DISCLAIMER
  • CONTACT
  • SEARCH!!!

Bitcoin logo Bitcoin BTC$78095.83

Ethereum logo Ethereum ETH$2177.93

Monero logo Monero XMR$379.04

Litecoin logo Litecoin LTC$55.92

Solana logo Solana SOL$86.16

Dogecoin logo Dogecoin DOGE$0.11

Bitcoin logo Bitcoin BTC$78095.83

Ethereum logo Ethereum ETH$2177.93

Monero logo Monero XMR$379.04

Litecoin logo Litecoin LTC$55.92

Solana logo Solana SOL$86.16

Dogecoin logo Dogecoin DOGE$0.11

BlackOps Nexus Market

React2Shell Exploited to Hijack NGINX Web Traffic


Hackers are exploiting the React2Shell flaw to inject malicious NGINX configs and hijack web traffic via attacker-controlled servers.

Security researchers have uncovered an ongoing web traffic hijacking campaign targeting NGINX servers and popular hosting control panels such as Baota (BT), with the goal of rerouting legitimate traffic through attacker-controlled infrastructure.

Datadog Security Labs reported that the activity is linked to exploitation of the critical React2Shell vulnerability. The attackers abuse malicious NGINX configuration files to intercept requests and proxy them to backend systems under their control.

“The malicious configuration sits between users and legitimate websites, silently redirecting traffic,” said security researcher Ryan Simon. “The campaign primarily targets Asian country-code TLDs like .in, .id, .pe, .bd, and .th, Baota-managed Chinese hosting environments, and government and education domains such as .gov and .edu.”

The attack relies on shell scripts that inject rogue “location” blocks into NGINX, an open-source reverse proxy and load balancer. These directives capture requests sent to specific URL paths and forward them to attacker-owned domains using the proxy_pass feature.

Researchers noted that the scripts form a multi-stage toolkit designed to establish persistence and automate the deployment of malicious NGINX configurations. Key components include:

zx.sh, the main controller, which executes later stages using tools like curl or wget, or falls back to raw TCP connections if those utilities are blocked
bt.sh, which specifically targets Baota (BT) Panel environments to overwrite NGINX configuration files
4zdh.sh, which scans common NGINX config paths and reduces errors during file creation
zdh.sh, which focuses on Linux and containerized NGINX deployments, particularly those serving .in and .id domains
ok.sh, which generates reports listing all active traffic hijacking rules on the system

“The toolkit combines target discovery, persistence mechanisms, and automated creation of malicious configuration files to sustain traffic redirection,” Datadog said.

The findings follow a GreyNoise report showing that just two IP addresses were responsible for 56% of observed React2Shell exploitation attempts two months after the vulnerability’s disclosure. Between January 26 and February 2, 2026, GreyNoise recorded exploitation activity from 1,083 unique source IPs.

According to the threat intelligence firm, the most active sources deployed different post-exploitation payloads. One delivered cryptomining software from staging servers, while the other established reverse shells back to the scanning IPs, indicating a preference for hands-on access over automated monetization.

The disclosure also comes amid a separate coordinated reconnaissance effort targeting Citrix ADC and NetScaler Gateway systems. That campaign leveraged tens of thousands of residential proxy IPs alongside a single Microsoft Azure address to identify exposed login interfaces.

“The operation ran in two modes,” GreyNoise said. “One used large-scale proxy rotation to discover login panels, while the other focused on rapid version enumeration from cloud infrastructure. Together, they point to a highly coordinated reconnaissance effort.”


Reports are sourced from official documents, law-enforcement updates, and credible investigations.

Discover additional reports, market trends, crime analysis and Harm Reduction articles on DarkDotWeb to stay informed about the latest dark web operations.


Related Articles

3 1605
Stolen Crypto Accounts Sold for $105 on Dark Web, Report Reveals
6 1353
Metadata Mistakes That Expose Criminals & OPSEC
5 1606
U.S. Sentences Russian Hacker to 6.75 Years Over Ransomware
0 1414
Obscura VPN passes first independent audit

Post navigation

The Rise and Fall of Dark Market →
← Dutch Police Arrest 10 in Major Drug Trafficking Probe
Featured Advertisement Featured Advertisement
Pitch Qubez
Nexus Market Prime Market Torzon CannaExpress MyDrugs Vortex Market Argo WeTheNorth Fawkes
HeyBud NordicMedTech WeAreAmsterdam

LATEST NEWS & ARTICLES

4 2146

NCA Launches New 12 Most Wanted Fugitives Appeal

 2026-05-16
6 2203

CISA Flags Cisco SD-WAN CVE-2026-20182 Exploits

 2026-05-16
6 2360

German DreamMarket Suspect Charged by US DOJ

 2026-05-13

Copyright © 2026 DarkDotWeb