logo

RondoDox Botnet Expands Scope With React2Shell Exploitation

ID: 04c31d51-ddd7-5cc1-a456-34efa13bb828

STIX ID: report--04c31d51-ddd7-5cc1-a456-34efa13bb828

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2026-01-05

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Researchers observed the RondoDox botnet actively exploiting the React2Shell vulnerability (CVE-2025-55182) and numerous other edge/IoT flaws to scan for vulnerable Next.js/React servers and deploy cryptominers, Mirai-based botnet variants, and a persistent loader that removes competing malware and enforces persistence across x86, x86_64, MIPS, ARM, and PowerPC devices; roughly 90,300 exposed vulnerable servers were identified and mitigations such as patching, network segmentation, WAFs, monitoring for unknown processes/cron jobs, and blocking C2 infrastructure are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.