HiddenOrbit
HiddenOrbit is a Chinese anonymization relay network used by state-sponsored threat actors. It is also referred to as RedRelay. The provided content states that HiddenOrbit/RedRelay infrastructure was observed conducting scanning and exploitation attempts against the React2Shell vulnerability (CVE-2025-55182) shortly after public disclosure. In reporting on React2Shell exploitation, HiddenOrbit (RedRelay) is listed among China-nexus threat actors or supporting infrastructure associated with exploitation activity. The content specifically attributes to HiddenOrbit early-stage scanning and exploitation attempts against vulnerable React Server Components and Next.js targets; no additional malware families, victim sectors, or sub-groups are directly specified for HiddenOrbit beyond the RedRelay alias.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Observables
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated in the report’s aggregated section with exploitation activity around React2Shell (CVE-2025-55182) and related RSC/Next.js vulnerabilities.
Named in an aggregated list of actors associated with React2Shell (CVE-2025-55182) exploitation activity.
Provides anonymization relay infrastructure for Chinese state-sponsored threat actors to conduct scanning and exploitation of CVE-2025-55182.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.