Skip to content

Executive Summary

An exposed server facilitated a large-scale, multi-victim exploitation and data collection operation utilizing an AI-assisted workflow. The operation leveraged tools like Claude Code and OpenClaw to orchestrate the process. A specific attack vector, React2Shell (CVE-2025-55182), was central to scanning millions of targets, resulting in over 900 confirmed exploits. Post-compromise activity focused on triaging access and concentrating collection efforts on organizations within the financial, cryptocurrency, and retail sectors. The operation successfully harvested credentials from numerous services, including AI platforms, cloud providers, payment systems, and databases. Further data recovery included sensitive business records from specific victims, such as financial statements and HR information. The operator maintained an organized infrastructure for command and control via Telegram, connecting the scanner fleet to a single human operator identifiable as "Dr. Tube."

Facts Only

* An exposed server was discovered used for multi-victim exploitation, staging, review, and validation.
* Claude Code and OpenClaw were used as an operator-side harness for exploitation workflow orchestration.
* A React2Shell (CVE-2025-55182) operation scanned millions of targets, confirming over 900 successful exploits via an automated pipeline.
* The operation involved hit scoring, alerting, and secret harvesting.
* Tens of thousands of .env files yielding credentials across AI, cloud, payments, messaging, and databases were harvested.
* Victim data clusters included financial, payroll, HR, CRM, communications, and other business-sensitive records for specific victims.
* The operator's infrastructure utilized Telegram alerting tied to the Bissa scanner ecosystem.
* The bot @bissapwnedbot was associated with the scanner alerting channel.
* The operation used S3-compatible Filebase for archiving harvested .env files.
* Artifacts show an organized workflow for exploiting targets, validating access, and prioritizing high-value collection.

Full Take

The narrative describes a shift from opportunistic hacking to industrialized, AI-assisted cyber operations, where the efficiency of automation is directly tied to maximizing the value extracted from compromised systems. The operation’s structure—using an AI (Claude Code) for workflow refinement and automation (OpenClaw) over a vulnerability scanner (React2Shell) to achieve mass credential harvesting—demonstrates a commoditization of exploitation techniques. This is not merely a sequence of hacks, but the development of a modular platform designed to operationalize reconnaissance into tangible, high-value assets across diverse sectors like finance and enterprise. The focus on triaging and prioritizing access suggests an adversarial understanding that raw compromise is less valuable than validated, actionable access bundles, which reinforces a pattern where actors seek not just entry, but privileged control surfaces. Furthermore, the integration of private communication channels (Telegram) for command and control reveals the necessity of compartmentalized, persistent C2 infrastructure outside traditional network monitoring to maintain operational cohesion across distributed systems. The tension lies between the sophisticated, disciplined workflow demonstrated by the operator and the inherent vulnerability present in the secrets themselves; while the method is highly engineered, the final cost remains concentrated on entities that fail to implement zero-trust principles effectively. What are the systemic costs imposed when exploiting these mass-scale workflows becomes normalized? How does this level of automation reshape the necessary skills for defenders?

From the original · The DFIR Report

Key Takeaways - We recently discovered an exposed server that was used for multi-victim exploitation, staging, review, and validation. - Claude Code and OpenClaw were used as an operator-side harness supporting exploitation activity and workflow orchestration. - We identified a large-scale React2Shell (CVE-2025-55182) operation that scanned millions of targets and confirmed 900+ successful…
Read the full story at thedfirreport.com

Sentinel — Human

Confidence

The text appears to be a forensic report synthesized from highly detailed technical evidence, exhibiting high organizational structure typical of investigative journalism or security research, despite the machine-assisted tooling mentioned in the content.

Signals Detected
low severity: Sentence length variance shows some natural variation mixed with dense technical listing.
low severity: Strong internal coherence linking specific technical artifacts (CVEs, tool names, Telegram handles) to the overall narrative structure.
medium severity: The density of specific data points (lists of services, file paths, bot names) suggests high human curation and source correlation rather than pure LLM generation.
low severity: The level of granular detail regarding S3 history phases, specific filenames, and named operator handles points toward deep investigative work, though the core technical narrative is well-formed.
Human Indicators
Specific attribution to named individuals (@BonJoviGoesHard, Renzon Cruz, Zach Stanford) and use of specific case identifiers (CVE numbers, precise file/bucket names) suggests primary human source material being synthesized.
Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting | Huntaegis