Skip to main content
Emerging ThreatsMalware & Ransomware

China-Linked Hackers Exploit Vulnerabilities in Record Time

Technician works on network equipment in a brightly-lit office data center.

“The speed of this response highlights their posture as adversaries who actively monitor vulnerability disclosures, rapidly validate exploitability, and pre-stage tooling in anticipation of a constantly changing attack surface,” the researchers noted in the CrowdStrike 2026 Threat Hunting Report, published on August 3.

Vault Panda and Genesis Panda: rapid, systematic weaponization

CrowdStrike’s analysis identifies China-affiliated groups Vault Panda and Genesis Panda as particularly fast actors in turning a newly disclosed web application flaw into active intrusions. The firm observed both groups deploying a mix of malicious tooling — including remote access trojans (RATs) — against victims after the public disclosure of the React2Shell exploit. Post-exploit activity recorded by the researchers included credential harvesting and other follow-on operations.

The report ties Vault Panda to UNC6588 and Genesis Panda to REF0657 and the label Earth Lamia, noting these clusters moved quickly relative to other actors who also leveraged React2Shell in the wild.

React2Shell: disclosure, patching and the compressed timeline

React2Shell, a critical web application vulnerability enabling unauthenticated remote code execution in React Server Components and Next.js applications, was disclosed in December 2025; patches were released at the same time. Despite simultaneous disclosure and patch availability, CrowdStrike found that China-nexus groups were capable of exploiting critical vulnerabilities within 24 hours of public disclosure.

That finding sits inside a broader trend: in H1 2026 CrowdStrike observed intrusions occurring within 48 hours of release in 88% of publicly disclosed vulnerability exploitations. The firm also recorded a 42% year‑over‑year increase in zero day exploitation from 2024 to 2025.

Frontier AI: accelerating both discovery and exploitation

CrowdStrike connects the acceleration in exploit timelines to the arrival of frontier AI designed for security research and vulnerability analysis. The report cites AI tools such as Anthropic’s Mythos and OpenAI’s GPT-5.4-Cyber and GPT-5.5-Cyber — models intended to find and fix vulnerabilities at scale — and warns of a consequential side-effect.

“Frontier models are likely contributing to the rising volume of disclosed vulnerabilities, exacerbating the challenges faced by network defenders as they attempt to cope with ever‑shrinking patch windows,” the researchers wrote. Importantly, the report states that observed rapid exploitation patterns predate the integration of frontier AI into vulnerability research, meaning the timeline could compress further as those tools propagate.

Identity attacks, LLMJacking and AI-enhanced vishing

Alongside faster technical exploits, CrowdStrike reports a dramatic rise in identity‑based attacks that it links largely to the use of AI. The firm highlights a growing trend of adversaries attempting to compromise victims’ corporate LLM API access in a technique the report names LLMJacking — where attackers gain access to a customer’s AI platform and then sabotage or monetize that access to cause financial harm.

One campaign recorded by CrowdStrike involved a threat actor sending nearly 200,000 API requests during a two‑minute period after obtaining elevated access to a cloud computing service that offered access to foundation models. The report also detected a doubling in intrusions that used vishing as the initial access vector in H1 2026 compared with H1 2025; these phone‑based impersonations are being enhanced by AI tools, such as deepfakes, and present few markers for defenders to detect.

What this means for technologists, policymakers, and affected enterprises

  • Technologists and security teams: expect exploitations to occur within 24–48 hours of disclosure and prioritize rapid patching, proactive monitoring for RATs and credential harvesting, and logging/telemetry to detect mass API request spikes like the 200,000‑call incident.
  • Policymakers and regulators: the report identifies frontier AI as a factor in rising vulnerability volume and faster exploitation; regulators may need to consider how AI tools alter disclosure timelines and the incentives around coordinated patching and disclosure.
  • Affected enterprises and procurement leaders: the threat picture now includes direct attacks on corporate AI platforms (LLMJacking) and an uptick in voice‑based fraud (vishing). Procurement and risk teams should evaluate third‑party cloud and AI providers for controls that limit elevated API abuse and monitor anomalous request volumes.

CrowdStrike’s August 3 report ties a specific exploit — React2Shell — to a larger pattern: rapid weaponization by nimble threat clusters, an uptick in zero‑day exploitation, and identity attacks amplified by AI. With intrusion windows commonly measured in hours and AI tools both discovering and exploiting flaws, defenders face materially smaller patch windows and new attack surfaces such as corporate LLM access. The next immediate task the report leaves clear is operational: detect anomalous API behavior, tighten controls around AI integrations, and assume attackers may move from disclosure to exploitation in a single day.

https://www.infosecurity-magazine.com/news/chinalinked-threat-actors/