JACKPOT PANDA
- Origin
- CN
- Profile updated
- 2026-07-28 03:00:02
Context
Jackpot Panda is a China-nexus state-sponsored APT primarily focused on cyber espionage against East and Southeast Asian entities, particularly in the online gambling sector and domestic security. They rapidly exploited CVE-2025-55182 using automated scanning, reconnaissance commands, and multi-vulnerability campaigns. Their activities have been linked to infrastructure associated with the exploitation of trojanized platforms and malware deployment, including SNOWLIGHT and VShell.
Exploited vulnerabilities
- CVE-2025-55182 (vulnerability)
Reports & references
- cloud.google.com — Threat Actors Exploit React2Shell Cve 2025 55182 (report)
- blog.polyswarm.io — Multiple Threat Actors Leveraging Cve 2025 55182 React2Shell (report)
- aws.amazon.com — China Nexus Cyber Threat Groups Rapidly Exploit React2Shell Vulnerability Cve 2025 55182 (report)