S-RM A.I CyberSecurity Scoring
S-RM
Company Information
Website:https://www.s-rminform.com
Employees number:375
Number of followers:49,118
NAICS:5616
Industry Type:Security and Investigations
Homepage:s-rminform.com
S-RM Risk Score (AI oriented)
Between 0 and 549
S-RMSecurity and Investigations
Updated:
31/03/2026
31/03/2026
543/1000
Critical
C
S-RM Global Score (TPRM)
xxxx
S-RMSecurity and Investigations
Score locked

S-RMCritical
Current Score
543C (CRITICAL)
01000
2 incidents
-147 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
558
MAY 2026
552
APRIL 2026
548
MARCH 2026
539
FEBRUARY 2026
538
JANUARY 2026
532
DECEMBER 2025
668
Ransomware
05 Dec 2025 • S-RM
S-RM: Critical React2Shell flaw exploited in ransomware attacks
Weaxor Ransomware Attack via React2Shell Vulnerability
521
HIGH-147
S-R1765994181
Weaxor Ransomware Exploits React2Shell Vulnerability in Rapid Attacks
A ransomware gang leveraged the critical React2Shell vulnerability (CVE-2025-55182) to breach corporate networks and deploy Weaxor ransomware in under a minute. The flaw, an insecure deserialization issue in React Server Components (RSC) and Next.js, allows unauthenticated remote code execution on vulnerable servers.
First disclosed in late 2024, React2Shell quickly became a target for both nation-state hackers—deploying cyberespionage tools like EtherRAT—and cybercriminals, who used it for cryptocurrency mining. On December 5, researchers at S-RM observed the Weaxor ransomware operation exploiting the vulnerability in a real-world attack.
Weaxor, a rebrand of the Mallox/FARGO ransomware (active since 2024), is a low-complexity operation targeting public-facing servers with opportunistic attacks. Unlike more advanced ransomware groups, it does not exfiltrate data or use double-extortion tactics, instead demanding relatively modest ransoms.
The attack unfolded rapidly:
- Initial access via React2Shell was followed by an obfuscated PowerShell command deploying a Cobalt Strike beacon for command-and-control (C2).
- The threat actor disabled Windows Defender’s real-time protection before executing the ransomware payload.
- Encrypted files received the .WEAX extension, with ransom notes (RECOVERY INFORMATION.txt) left in affected directories.
- The attackers wiped volume shadow copies and cleared event logs to hinder recovery and forensic analysis.
Notably, the breach remained contained to the vulnerable endpoint, with no observed lateral movement. However, the same compromised host was later targeted by additional attackers, underscoring the high demand for React2Shell exploits.
S-RM researchers recommend monitoring for suspicious process creation—particularly cmd.exe or PowerShell spawned from node.exe—as well as unusual outbound connections, disabled security tools, and log tampering. While patching is critical, defenders should also review EDR telemetry for signs of exploitation.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
NOVEMBER 2025
668
OCTOBER 2025
667
SEPTEMBER 2025
665
AUGUST 2025
663
JULY 2025
661
MARCH 2025
761
Ransomware
01 Mar 2025 • S-RM
S-RM
Sophisticated Ransomware Attack on S-RM
651
CRITICAL-110
S-R226031025
S-RM encountered a sophisticated ransomware attack initiated by the Akira group, involving the exploitation of IoT devices, specifically an insecure webcam, to bypass EDR tools and encrypt files on the network. This innovative tactic allowed the attackers to overcome security measures and establish persistent access through AnyDesk.exe and lateral movement via RDP. The incident required a response team to address the breach and implement new security strategies. The data exfiltration and encryption caused considerable disruption to the company's operations, likely affecting its finances and reputation due to the sophisticated nature of the attack.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for S-RM ??
What was S-RM's A.I Rankiteo Cyber Score in May 2026 ??
What was S-RM's A.I Rankiteo Cyber Score in April 2026 ??
What was S-RM's A.I Rankiteo Cyber Score in March 2026 ??
What was S-RM's A.I Rankiteo Cyber Score in February 2026 ??
What was S-RM's A.I Rankiteo Cyber Score in January 2026 ??
What was S-RM's A.I Rankiteo Cyber Score in December 2025 ??
What was S-RM's A.I Rankiteo Cyber Score in November 2025 ??
What was S-RM's A.I Rankiteo Cyber Score in October 2025 ??
What was S-RM's A.I Rankiteo Cyber Score in September 2025 ??
What was S-RM's A.I Rankiteo Cyber Score in August 2025 ??
What was S-RM's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on S-RM's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with S-RM ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view S-RM's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?