MINOCAT
MINOCAT is a tunneling utility/backdoor used in post-exploitation activity following exploitation of the React Server Components vulnerability CVE-2025-55182 ("React2Shell"). It has been observed in campaigns attributed to the China-nexus espionage cluster UNC6600, and broader reporting also places it among tooling used by China-linked actors exploiting this flaw globally. Google Threat Intelligence Group described MINOCAT as a tunneler based on Fast Reverse Proxy (FRP); specifically, it is a 64-bit ELF executable for Linux that includes a custom "NSS" wrapper and an embedded open-source FRP client for tunneling. Its purpose is to establish persistence and covert network access on compromised systems, maintaining hidden access to victim networks.
Observed delivery involved attackers exploiting CVE-2025-55182 to gain unauthenticated remote code execution against vulnerable React/Next.js workloads, then executing bash scripts that downloaded the MINOCAT binary. In UNC6600 activity, the script created a hidden directory at $HOME/.systemd-utils, killed processes named "ntpclient," and established persistence through a new cron job, a systemd service, and malicious commands inserted into the user’s shell configuration so MINOCAT would run in new shells. High-confidence indicators of compromise associated with this activity include the hidden directory $HOME/.systemd-utils, unauthorized termination of "ntpclient," and malicious modifications to shell startup files such as $HOME/.bashrc. The malware targets Linux systems and has been used in espionage-oriented intrusions against globally exposed, unpatched React and Next.js environments.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Vulnerabilities exploited
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Since exploitation began last week, our team at Google Threat Intelligence Group (GTIG) has been tracking widespread activity as multiple threat clusters race to leverage React2Shell (CVE-2025-55182). | Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.
Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.
Techniques & procedures
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
1 technique“React2Shell exploitation continues… globally exploited… victims triaged… distinct campaigns leveraging this vulnerability…” and “threat actor use React2Shell as the initial access vector in a ransomware attack.”
Execution
2 techniques"The threat actor retrieved and executed a bash script used to create a hidden directory... kill any processes... download a MINOCAT binary..."
Persistence
2 techniquesPrivilege Escalation
2 techniquesCommand and Control
2 techniquesChina-Nexus Espionage: Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.
"execute a command using cURL or wget to retrieve a script that then downloaded and executed a SNOWLIGHT downloader payload"; and "download a MINOCAT binary"
Impact
1 techniqueRecent activity
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tunneling tool deployed in campaigns exploiting React2Shell (CVE-2025-55182) per the referenced reporting.
A tunneling utility delivered by UNC6600 for network tunneling and evasion.
Minocat is a tunneler malware used to establish persistence on infected systems, likely providing covert access or data exfiltration channels.
MINOCAT is tunneling software deployed by the Chinese threat group UNC6600 to facilitate covert communications and data exfiltration during exploitation of the React2Shell vulnerability.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.