Escalating Kubernetes Attacks: React2Shell (CVE-2025-55182), Slow Pisces, and Cloud-Native Threat Actors — Threadlinqs Intelligence
As of 2026-05-30, Escalating Kubernetes Attacks: React2Shell (CVE-2025-55182), Slow Pisces, and Cloud-Native Threat Actors is a critical-severity vulnerability threat attributed to Slow Pisces (North Korea / China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-0327 · Severity: CRITICAL · CVSS: 10 · Status: ACTIVE · Category: VULNERABILITY
Attribution: Slow Pisces · North Korea / China · FINANCIAL
Unit 42 documents a 282% year-over-year surge in Kubernetes token-theft operations driven by multiple threat actors, anchored by CVE-2025-55182 (React2Shell) — a CVSS 10.0 insecure deserialization
Unit 42 threat intelligence reports a dramatic escalation in attacks targeting Kubernetes environments throughout 2025, with 467,658 alerts recorded compared to 122,465 in 2024 — a 282% year-over-year increase. The surge peaked in December 2025 with 275,210 alerts driven primarily by mass exploitation of CVE-2025-55182 (React2Shell). Suspicious activity related to potential service account token theft was observed in 22% of monitored cloud environments, with the IT sector absorbing 78% of targeting activity.
CVE-2025-55182 (React2Shell) is a critical pre-authentication remote code execution vulnerability scoring CVSS 10.0 that affects insecure deserialization in the React Server Components (RSC) Flight protocol. The flaw resides in react-server-dom-webpack and react-server-dom-turbopack packages across React versions 19.0.0 through 19.2.0 and Next.js versions 15.0.0 through 16.0.7. The exploit constructs a gadget chain during deserialization that replaces legitimate objects with attacker-controlled gadgets, ultimately invoking the Function() constructor to achieve arbitrary code execution. Exploitation requires only the next-action HTTP header — no authentication, no valid action name — making it trivially exploitable at scale. Disclosed December 3, 2025, active exploitation was observed by December 5-7, 2025. CISA added it to the Known Exploited Vulnerabilities catalog on December 5 with remediation due December 12. Post-exploitation activities include cloud metadata service reconnaissance (169.254.169.254), Sliver C2 deployment, XMRig cryptominer installation, fileless backdoors via Node.js runtime monkey-patching, and magic-path webshells monitoring /favicon.login.ico.
Slow Pisces (also tracked as Lazarus, TraderTraitor, Jade Sleet, HIDDEN COBRA) is a North Korean state-sponsored threat group attributed to the Reconnaissance General Bureau. In February 2025, the group executed the $1.5 billion Bybit cryptocurrency heist by compromising the Safe{Wallet} development environment through social engineering, injecting malicious JavaScript to redirect ETH transactions. In May 2025, Slow Pisces breached BitoPro through social engineering of a cloud operations employee. By mid-2025, the group was documented conducting Kubernetes post-exploitation operations against cryptocurrency exchanges — extracting service account tokens, exploiting RBAC misconfigurations for privilege escalation, and pivoting from Kubernetes clusters to cloud infrastructure. Their second-stage payload RN Stealer targets SSH keys, iCloud data, Kubernetes configs, and AWS credentials.
SCARLETEEL is a persistent cloud-native threat operation documented by Sysdig that targets AWS Fargate and Kubernetes environments. The operation leverages the Peirates post-exploitation framework (S0683) for Kubernetes enumeration and resource discovery, combined with AWS CLI and Pacu for cloud exploitation. SCARLETEEL exploits JupyterLab notebook containers in Kubernetes clusters, attempts IMDSv2 exploitation for credential theft, and has demonstrated ability to bypass IAM controls through case-sensitivity bugs in username policies.
TeamTNT (G0139) is an established cryptojacking group that deploys the Hildegard malware targeting Kubernetes environments. They abuse Peirates for reconnaissance and deploy privileged containers mounting victim filesystems for host escape. TeamPCP (also known as PCPcat, ShellForce, DeadCatx3) is a newer threat cluster active since at least July 2025 that operates a worm-driven campaign compromising Docker APIs, Kubernetes clusters, Ray dashboards, and Redis servers. Their tooling includes proxy.sh for propagation, kube.py for Kubernetes credential harvesting and API-based resource discovery, scanner.py, react.py for React2Shell exploitation, and pcpcat.py. Around December 25, 2025, TeamPCP weaponized CVE-2025-55182 at scale. In early 2026, the group escalated to supply chain attacks targeting Aqua Security Trivy, Checkmarx KICS, BerriAI LiteLLM,
Target sectors: information-technology, financial, communication-services, consumer-discretionary, industrials, energy, healthcare, government, cryptocurrency
Target regions: North America, Europe, East Asia, South Korea, Canada, Serbia, United Arab Emirates, Global
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2025-55182, T1190, T1078, T1609, T1059, T1098, T1610, T1611, T1134, T1550, T1528