Bissa scanner is a large-scale opportunistic exploitation and secret-harvesting operation centered on React2Shell (CVE-2025-55182), with additional capability development for exploiting W3 Total Cache via CVE-2025-9501. The operation used a mature, modular workflow to scan internet-facing systems at scale, exploit vulnerable targets, enumerate exposed configuration data, validate compromised access, and prioritize victims for deeper follow-on review. Recovered operational artifacts indicate more than 900 confirmed compromises and collection of tens of thousands of exposed environment files over a concentrated period. The platform’s primary objective was acquisition and triage of secrets and access material. Collection focused on environment files, cloud metadata, Kubernetes service-account context, local credential stores, database access, payment-platform credentials, authentication-platform secrets, messaging and collaboration tokens, and cryptocurrency-related material. The operator did not merely gather data opportunistically; the workflow included validation, scoring, and victim prioritization, indicating a structured post-compromise process aimed at identifying higher-value organizations and monetizable access. Operational tooling showed an AI-enabled workflow used to improve exploitation reliability and collection efficiency. Embedded use of Claude Code and OpenClaw supported troubleshooting, orchestration, code review, and refinement of the acquisition pipeline. Telegram-based alerting and operator notification were integrated into the workflow to summarize successful compromises and exposed secret surfaces. Observed victim data and prioritization patterns indicate particular interest in financial services, digital-asset and cryptocurrency businesses, payroll and HR-related platforms, and retail or payment-processing environments. Recovered victim clusters included sensitive financial, payroll, HR, CRM, communications, and banking-related data, consistent with a financially motivated access-and-data theft operation rather than espionage. Known associated identifiers include the public Telegram handle “Dr. Tube” and the username @BonJoviGoesHard, as well as bots used for alerting and workflow control. High-confidence evidence ties the operation to infrastructure and hosting artifacts associated with Turkey. No high-confidence evidence in the available material supports ransomware deployment or extortion activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.