PULSE NAME
AI/LLM-Generated Malware Used to Exploit React2Shell
WHITE PetrP.73 2026-02-16 Modified: 2026-03-18
22
IOCs
MEDIUM VOLUME
Recent observations from Darktrace's honeypot network, "CloudyPots," highlight the use of AI-generated malware exploiting vulnerable Docker environments, specifically the Docker daemon exposed without authentication. This configuration allows attackers to discover the daemon and create containers through the Docker API, establishing initial access to the system. The central component of the intrusion was a Python payload that acted as the execution mechanism. The payload was notably obfuscated, indicating a deliberate effort to disguise its functionality. Throughout the malware sample, there was a lack of embedded spreading logic, which is typically found in Docker malware. This omission suggests that the attackers utilized a separate remote spreading tool instead.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (4 / 22 total)
All URL CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
URL https://smplu.link/dockerzero. 2026-02-16
URL http://134.122.13.34:8979/c 2026-02-16
URL http://195.154.119.194/index.js 2026-02-16
URL http://217.76.57.78:8009/index.js 2026-02-16