RondoDoX Botnet Weaponizing a Critical React2Shell Vulnerability to Deploy Malware
ID: c80e77a5-9d9f-522d-b75b-b2180eca3418
STIX ID: report--c80e77a5-9d9f-522d-b75b-b2180eca3418
Feed Name: cybersecurityNews.com
RondoDoX is a sustained botnet campaign active from March to December 2025 that scanned for and exploited vulnerable web applications and IoT devices to deploy multi-architecture ELF payloads, cryptominers, and botnet agents; the attackers escalated from manual testing to automated daily and then hourly exploitation, operated multiple overlapping C2 servers, and in December weaponized a critical Next.js vulnerability (React2Shell). Recommended mitigations include patching, network segmentation, WAF deployment, monitoring for suspicious process execution and blocking identified C2 infrastructure at the perimeter.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
