logo

“RondoDoX” Strikes Back: Exposed Logs Reveal Massive 9-Month Campaign Targeting Next.js and IoT

ID: e7e7a80a-aba2-5601-8df3-88e1a578dcf0

STIX ID: report--e7e7a80a-aba2-5601-8df3-88e1a578dcf0

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2025-12-31

Date Updated: 2026-04-22

Author: Ddos

...
...

The CloudSEK report describes a nine-month RondoDoX botnet campaign (Mar–Dec 2025) that broadened from automated IoT/router compromises to enterprise Next.js servers by weaponizing a React2Shell prototype-pollution/deserialization RCE. Researchers recovered exposed C2 logs showing active exploitation, multi-architecture binaries (x86, x86_64, MIPS, ARM, PowerPC), automated hourly exploitation attempts, and aggressive persistence behaviors including killing non-whitelisted processes; the activity poses critical RCE exposure to Next.js Server Actions and a continued widespread threat to IoT and web infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.