RondoDox botnet exploits React2Shell flaw to breach Next.js servers
ID: 635d8404-df4d-5ddd-9dda-344698a752dd
STIX ID: report--635d8404-df4d-5ddd-9dda-344698a752dd
Feed Name: Bleeping Computer
CloudSEK and other analysts report that the RondoDox botnet has been actively exploiting the critical React2Shell RCE (CVE-2025-55182) against Next.js servers since early December, deploying coinminers, a botnet loader/health-checker, and a Mirai variant, while also conducting hourly IoT exploitation waves to grow its botnet; Shadowserver reports over 94,000 exposed assets vulnerable to the flaw and researchers detail payload paths, persistence mechanisms, and cleanup of competing malware, with recommended mitigations including patching Next.js Server Actions, isolating IoT devices, and monitoring for suspicious processes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
