logo

RondoDox botnet exploits React2Shell flaw to breach Next.js servers

ID: 635d8404-df4d-5ddd-9dda-344698a752dd

STIX ID: report--635d8404-df4d-5ddd-9dda-344698a752dd

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-12-31

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

CloudSEK and other analysts report that the RondoDox botnet has been actively exploiting the critical React2Shell RCE (CVE-2025-55182) against Next.js servers since early December, deploying coinminers, a botnet loader/health-checker, and a Mirai variant, while also conducting hourly IoT exploitation waves to grow its botnet; Shadowserver reports over 94,000 exposed assets vulnerable to the flaw and researchers detail payload paths, persistence mechanisms, and cleanup of competing malware, with recommended mitigations including patching Next.js Server Actions, isolating IoT devices, and monitoring for suspicious processes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.