Bissa Scanner — AI-Assisted Mass Exploitation and Credential Harvesting Campaign (@BonJoviGoesHard / Dr. Tube) — Threadlinqs Intelligence
As of 2026-05-30, Bissa Scanner — AI-Assisted Mass Exploitation and Credential Harvesting Campaign (@BonJoviGoesHard / Dr. Tube) is a high-severity threat intel threat attributed to BonJoviGoesHard (N/A), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-0411 · Severity: HIGH · CVSS: 9 · Status: MONITORING · Category: THREAT_INTEL
Attribution: BonJoviGoesHard · N/A · FINANCIAL
The DFIR Report disclosed Bissa Scanner — an exposed operator-run, AI-assisted mass-exploitation platform attributed to a single Telegram-handled actor (@BonJoviGoesHard / Dr. Tube) that weaponized
On 2026-04-22, The DFIR Report published a deep-dive disclosure of a mass-exploitation and secret-harvesting pipeline branded by its own operator as Bissa Scanner. The research team recovered the operator's internal tooling, scanner codebase, Telegram bot telemetry, and staging infrastructure after the operator inadvertently exposed a leased control-plane endpoint. The campaign is attributed — with HIGH confidence — to a single individual operating under the Telegram handles @BonJoviGoesHard and Dr. Tube, working from a Linux workstation that doubled as the scanner's orchestrator.
The operator's primary weaponization target was CVE-2025-55182 (React2Shell), a remote code execution flaw in Next.js middleware request handling that allows an unauthenticated attacker to smuggle an x-middleware-subrequest header chain, bypass authentication and middleware gating, and reach internal server-rendered routes that evaluate attacker-controlled input as JavaScript. A secondary exploit module weaponized CVE-2025-9501, an unauthenticated command-injection vulnerability in the W3 Total Cache WordPress plugin's CDN purge endpoint. The scanner fingerprinted both stacks via HTTP banner heuristics and favicon hashing, then launched exploit leases against candidate targets in staggered batches to avoid upstream rate-limiting.
Successful compromise on a Next.js target resulted in the deployment of a staged dropper that walked the application root for .env, .env.local, .env.production, next.config.js, and package.json, recursively pulled node_modules/.bin metadata, and compressed findings into a numbered ZIP (bissa-batch-NNNN.zip) uploaded to the operator's Filebase S3 bucket bissapromax. On WordPress/W3 Total Cache targets the same pipeline harvested wp-config.php, wp-content/uploads, mu-plugins, and any detected AWS/Stripe/SendGrid keys in wp_options.
The novel TTP disclosed by the report is the operator's tight coupling of Claude Code and OpenClaw as an AI-assisted engineering harness for the scanner itself — not for victim compromise, but for operator productivity. The DFIR Report recovered conversation transcripts showing the operator using Claude Code to refactor the lease/acknowledgement queueing logic, debug a race condition in the exploit-worker pool, write benchmark harnesses to rank target-generation strategies, and translate error messages from the scanner's Go-based HTTP worker into Python for triage. OpenClaw was used as a sandboxed container harness to iterate on scanner modules without polluting the operator's host. This pattern — using agentic coding assistants to compress the operator development cycle for offensive tooling — represents an inflection point in the industrialization of opportunistic mass exploitation.
Telemetry recovered from the two Telegram bots (@bissapwned_bot for hit alerts, @bissa_scan_bot for scan-queue control) confirms 900+ successful compromises across 400+ exfil batches, 30,000+ unique .env files, and 65,000+ total archived file entries. Victim geography skews toward North America and Europe, with heavy representation in financial services, cryptocurrency custodians and exchanges, retail e-commerce, and payroll/HR SaaS. Recovered harvested credentials include AWS access keys, Stripe live keys, SendGrid API tokens, Anthropic and OpenAI API keys, GitHub personal access tokens, Auth0 and Okta client secrets, and private keys for MetaMask/Coinbase/custodial wallets. At least 40 of the AWS keys were observed being reused by the operator within 24 hours for secondary enumeration against S3 and IAM, indicating hands-on-keyboard follow-through rather than pure bulk hoarding.
The DFIR Report's exposure has burned the operator's current infrastructure (Filebase bucket, Telegram bots, and the leased VPS fronting the scanner control plane), but the operator's tooling has been open enough — and replicable enough — that copycat deployment by other opportunistic actors should be expected within weeks. Defenders are
Weaknesses (CWE)
CWE-290, CWE-78, CWE-94, CWE-288, CWE-200
Target sectors: financial-services, cryptocurrency, retail, payroll-hr, ai-platforms, cloud-services, e-commerce, fintech
Target regions: North America, Europe, United Kingdom, Australia
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, CVE-2025-55182, CVE-2025-9501, T1595, T1595.002, T1592, T1583.006, T1587.001, T1588.005, T1608.001, T1190, T1078.004, T1059.004