[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f-9uqpdQR4_qaluRdnj15-YdonXNmBpNo6iGZ3hhojE8":3},{"article":4,"iocs":44,"watch_terms":53},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":28},"29302239-6631-46eb-8e4e-3130189fc420","\"The scanner relies on an acquirer file containing targets and a lease file defining the exploit...","the-scanner-relies-on-an-acquirer-file-containing-targets-and-a-lease-file-defin-468022","\"The scanner relies on an acquirer file containing targets and a lease file defining the exploit type. These files show the operator obtaining target feeds from ZIP archives hosted on cs2[.]ip[.]thc[.]org, assigning the cve_2025_55182 module, and deploying a payload intended to https:\u002F\u002Ft.co\u002F7SWuIpohv1","A malware scanner has been discovered leveraging CVE-2025-55182 to target systems. The attack infrastructure uses acquirer and lease configuration files to obtain target lists from ZIP archives hosted on cs2.ip.thc.org, with payloads deployed via compromised or attacker-controlled domains. The campaign demonstrates active exploitation of the vulnerability with organized targeting methodology.","Malware scanner exploits CVE-2025-55182 using target feeds from thc.org infrastructure.",null,"https:\u002F\u002Fx.com\u002FTheDFIRReport\u002Fstatus\u002F2047647438693872055","https:\u002F\u002Fpbs.twimg.com\u002Fmedia\u002FHGq0eXFXoAAmLBL.jpg","2026-04-24T12:02:47+00:00","2026-04-24T13:00:12.447309+00:00",8,[18,21],{"name":19,"type":20},"CVE-2025-55182 Scanner Campaign","campaign",{"name":22,"type":23},"Malware Scanner with Modular Exploit Framework","technology","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":24,"icon":11,"name":26,"slug":27},"Malware","malware",[29,34,39],{"category":30},{"id":31,"icon":11,"name":32,"slug":33},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",{"category":35},{"id":36,"icon":11,"name":37,"slug":38},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":40},{"id":41,"icon":11,"name":42,"slug":43},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[45,49],{"type":46,"value":47,"context":48},"domain","cs2.ip.thc.org","C2\u002Fpayload distribution domain hosting target feed ZIP archives",{"type":50,"value":51,"context":52},"cve","CVE-2025-55182","Vulnerability exploited by malware scanner module in active campaign",[]]