DFIR Report: OpenClaw/Claude-Code assisted attack

Wake up babe, new DFIR Report just dropped:

Looks like an attacker left an infrastructure server exposed. Thank you for your service, bad guy.

4 Likes

Rereading this, I found an interesting nugget. I believe this is the first evidence I’ve seen in writing of successful exploitation of React2Shell. At the time of the vulnerability’s disclosure, everyone was citing attempt or scanning stats, but couldn’t provide evidence of success.

Well, sorta.

While some victim environments showed direct evidence of exploitation through the scanner workflow, other clusters could not be confirmed.

The “scanner” used React2Shell, so ostensibly this means the exploit attempt was directly successful. Would still love to see more concrete evidence.

Why do I care? Because evidence of attack is not evidence of exploitation, regardless of what the big sensor firms would have you believe.

2 Likes