HISONIC is a Go-based backdoor associated with the China-nexus threat cluster UNC6603. It has been observed in post-exploitation activity following rapid exploitation of the React Server Components remote code execution vulnerability CVE-2025-55182 (React2Shell), where attackers deployed it onto compromised Linux-hosted web infrastructure alongside other tooling such as SNOWLIGHT, MINOCAT, COMPOOD, ANGRYREBEL.LINUX, CrossC2, and cryptocurrency miners. HISONIC is used to establish persistent remote access on compromised systems and has been described as blending malicious traffic with legitimate network activity by leveraging trusted cloud services, including Cloudflare Pages and GitLab, to retrieve encrypted configuration and conceal command-and-control communications. Reported targeting includes cloud and internet-facing workloads, including AWS and Alibaba Cloud environments in the Asia-Pacific region. Its use is consistent with espionage-oriented intrusion activity focused on maintaining covert access after initial compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
2025年12月3日(現地時間)、React Server Components(RSC)における認証不要のリモートコード実行の脆弱性(CVE-2025-55182)が公開されました。JPCERT/CCでは、この攻撃の被害報告を複数受けています。 | 2025-12-06 09:53、10:09、11:00 HISONIC(javax)バックドアの設置
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Golangで作成されたバックドアとして記載され、React2Shell悪用後に設置された。本文ではUNC6603が利用すると言われているHISONICバックドアと説明されている。
Golang-based backdoor installed after exploitation to provide remote access/persistence on the compromised host.
Backdoor deployed in campaigns exploiting React2Shell (CVE-2025-55182) per the referenced reporting.
A Go-based backdoor that retrieves encrypted configuration from Cloudflare Pages and GitLab, designed to blend in with legitimate network activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.