Bissa Scanner — AI-Assisted Mass Exploitation of CVE-2025-55182 (React Server Components RCE) and CVE-2025-9501 (W3 Total Cache) — Threadlinqs Intelligence
As of 2026-05-30, Bissa Scanner — AI-Assisted Mass Exploitation of CVE-2025-55182 (React Server Components RCE) and CVE-2025-9501 (W3 Total Cache) is a critical-severity vulnerability threat attributed to BonJoviGoesHard, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 29 indicators of compromise.
Threat ID: TL-2026-0428 · Severity: CRITICAL · CVSS: 10 · Status: MONITORING · Category: VULNERABILITY
Attribution: BonJoviGoesHard · FINANCIAL
AI-orchestrated mass-exploitation and credential-harvesting campaign operated by Telegram handle @BonJoviGoesHard (Dr. Tube). The scanner abuses CVE-2025-55182 (React Server Components / Next.js
Bissa Scanner is an active, lone-operator mass-exploitation framework that weaponizes CVE-2025-55182 — a CVSS 10.0 pre-auth remote code execution flaw in React Server Components (RSC) bundlers and routing infrastructure used by Next.js, Remix, and other RSC-aware frameworks — together with CVE-2025-9501, a CVSS 9.0 unauthenticated command-injection issue in WordPress plugin W3 Total Cache (versions <2.8.13). The campaign is run by Telegram user @BonJoviGoesHard (display name ''Dr. Tube'', User ID 1609309278) and supported by an automated bot army centered on @bissapwned_bot (Bot ID 8798206332) for victim alerting and @bissa_scan_bot for AI-control orchestration.
The scanner ingests target lists from acquirer endpoints — most recently denemekulubum.com.tr/acquirer/ (formerly wiprz.com/acquirer/) and target feeds distributed via cs2.ip.thc.org — and assigns work via lease files keyed to exploit modules (e.g., cve_2025_55182). After RCE is achieved, payloads enumerate .env files, cloud metadata services (AWS IMDS, GCP metadata, Azure IMDS), Kubernetes service-account tokens, credential stores, database/Redis access, and cryptocurrency wallets. Harvested .env files land in a results/ directory on the operator''s scanner hosts where a watcher batches them into env-batch-*.zip archives and uploads to Filebase (s3.filebase.com) under the bissa, bissa2, and bissapromax buckets. Bissa was first stood up September 2025; bissa2 in November 2025; bissapromax in December 2025 — the latter remains the active live archive. Telegram alerts deliver per-hit notifications to chat ID 1609309278.
Forensic recovery from the exposed buckets surfaced 13,000+ files across 150+ directories, 400+ raw env-batch-*.zip objects, 30,000+ distinct .env filenames, and 65,000+ archived file entries. The intensive harvesting window observed ran April 10–21, 2026, immediately preceding The DFIR Report''s public exposure on 2026-04-22. Confirmed victim profiles include: a mid-sized US tax-resolution and financial-advisory firm (Plaid tokens, linked bank accounts, IRS transcripts, ACH records, Twilio call logs, Salesforce contacts, SSN/DOB case data); a large digital-asset and enterprise-finance company (authenticated Oracle Fusion REST exports — suppliers, invoices, POs, payments, bank accounts); and a mid-sized payroll/HR/stablecoin payments platform (payroll records, settlement data, Fireblocks integration material, HRIS data).
The most novel element is the operator''s integration of large-language-model tooling into the offensive workflow. Claude Code (claude-sonnet-4-6) was used for scanner code review, troubleshooting, and documentation, while OpenClaw provided a local AI-control surface with a websocket gateway and browser automation layer for exploit triage. A helper script, claude_env_fix.sh, was used to repair malformed .env captures before secret-harvest parsing. This places Bissa in a small but growing class of offensive operations using consumer LLM coding agents as productivity multipliers for scanner development and triage.
Downstream blast radius is severe: harvested credentials enable full takeover of the victim''s AWS, GCP, Azure, Cloudflare, Stripe, PayPal, Auth0/Okta, Clerk, Supabase, MongoDB, Plaid, Fireblocks, and GitHub tenants — meaning the campaign functions as an enabler for ransomware, BEC, payment fraud, crypto theft, and supply-chain compromise via stolen GitHub tokens. CVE-2025-55182 was added to the CISA Known Exploited Vulnerabilities catalog on 2025-12-05 with a 2025-12-19 federal remediation deadline; W3 Total Cache CVE-2025-9501 has been observed under active exploitation since the v2.8.13 patch in early 2026. Defenders should patch RSC-using applications to the React 19.x security release line and W3 Total Cache to >=2.8.13, block egress to s3.filebase.com from production tenants where unjustified, hunt for env-batch-*.zip and claude_env_fix.sh artifacts on web-tier hosts, rotate every secret class listed in this advisory, an
Weaknesses (CWE)
CWE-502, CWE-78, CWE-77, CWE-200, CWE-918
Target sectors: financial, fintech, payments, payroll, tax-services, cryptocurrency, saas, e-commerce, retail, hr-tech, developer-tools
Target regions: North America, Europe, Asia, Global
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 29 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2025-55182, CVE-2025-9501, T1595, T1595.002, T1592, T1583.006, T1587.004, T1588.002, T1190, T1059.004, T1059.007, T1078.004