“RondoDoX” Strikes Back: Exposed Logs Reveal Massive 9-Month Campaign Targeting Next.js and IoT
ID: e7e7a80a-aba2-5601-8df3-88e1a578dcf0
STIX ID: report--e7e7a80a-aba2-5601-8df3-88e1a578dcf0
Feed Name: securityonline.info
The CloudSEK report describes a nine-month RondoDoX botnet campaign (Mar–Dec 2025) that broadened from automated IoT/router compromises to enterprise Next.js servers by weaponizing a React2Shell prototype-pollution/deserialization RCE. Researchers recovered exposed C2 logs showing active exploitation, multi-architecture binaries (x86, x86_64, MIPS, ARM, PowerPC), automated hourly exploitation attempts, and aggressive persistence behaviors including killing non-whitelisted processes; the activity poses critical RCE exposure to Next.js Server Actions and a continued widespread threat to IoT and web infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
