Executive Summary
Facts Only
* An exposed server was discovered used for multi-victim exploitation, staging, review, and validation.
* Claude Code and OpenClaw were used as an operator-side harness for exploitation workflow orchestration.
* A React2Shell (CVE-2025-55182) operation scanned millions of targets, confirming over 900 successful exploits via an automated pipeline.
* The operation involved hit scoring, alerting, and secret harvesting.
* Tens of thousands of .env files yielding credentials across AI, cloud, payments, messaging, and databases were harvested.
* Victim data clusters included financial, payroll, HR, CRM, communications, and other business-sensitive records for specific victims.
* The operator's infrastructure utilized Telegram alerting tied to the Bissa scanner ecosystem.
* The bot @bissapwnedbot was associated with the scanner alerting channel.
* The operation used S3-compatible Filebase for archiving harvested .env files.
* Artifacts show an organized workflow for exploiting targets, validating access, and prioritizing high-value collection.
Full Take
From the original · The DFIR Report
Key Takeaways - We recently discovered an exposed server that was used for multi-victim exploitation, staging, review, and validation. - Claude Code and OpenClaw were used as an operator-side harness supporting exploitation activity and workflow orchestration. - We identified a large-scale React2Shell (CVE-2025-55182) operation that scanned millions of targets and confirmed 900+ successful…Read the full story at thedfirreport.com
Sentinel — Human
The text appears to be a forensic report synthesized from highly detailed technical evidence, exhibiting high organizational structure typical of investigative journalism or security research, despite the machine-assisted tooling mentioned in the content.
