logo

RondoDox Botnet is Using React2Shell to Hijack Thousands of Unpatched Devices

ID: 3660bc49-9da5-5843-befd-76fdf81e072d

STIX ID: report--3660bc49-9da5-5843-befd-76fdf81e072d

Feed Name: HackRead

Threat Score
78/100

Date Published: 2026-01-03

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

RondoDox is actively exploiting the critical Next.js React2Shell vulnerability (CVE-2025-55182) to build a large botnet, targeting websites, home routers, and IoT devices; Shadowserver observed over 90,300 vulnerable systems. The campaign progressed from manual testing to automated mass scanning and deployment of multiple malware variants (cryptominer, Mirai-like spreader, and a competitive 'health checker') across diverse architectures, with recommendations to apply Next.js patches and segment/update home devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.