JACKPOT PANDA

Origin
CN
Profile updated
2026-07-28 03:00:02

Context

Jackpot Panda is a China-nexus state-sponsored APT primarily focused on cyber espionage against East and Southeast Asian entities, particularly in the online gambling sector and domestic security. They rapidly exploited CVE-2025-55182 using automated scanning, reconnaissance commands, and multi-vulnerability campaigns. Their activities have been linked to infrastructure associated with the exploitation of trojanized platforms and malware deployment, including SNOWLIGHT and VShell.

Exploited vulnerabilities

  • CVE-2025-55182 (vulnerability)

Reports & references

  • cloud.google.com — Threat Actors Exploit React2Shell Cve 2025 55182 (report)
  • blog.polyswarm.io — Multiple Threat Actors Leveraging Cve 2025 55182 React2Shell (report)
  • aws.amazon.com — China Nexus Cyber Threat Groups Rapidly Exploit React2Shell Vulnerability Cve 2025 55182 (report)

External references