logo

RondoDox botnet malware now hacks servers using XWiki flaw

ID: e417bf48-184e-5fd0-b281-9d2bd565fe33

STIX ID: report--e417bf48-184e-5fd0-b281-9d2bd565fe33

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-11-17

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

Researchers observed active exploitation of a critical XWiki RCE (CVE-2025-24893) beginning in late October/early November, with the RondoDox botnet and other actors delivering a first-stage downloader via base64-encoded Groovy injection to the XWiki SolrSearch endpoint, leading to remote shell execution, cryptocurrency miner deployments, and reverse-shell attempts; affected XWiki versions are prior to 15.10.11 and 16.4.1, and immediate patching and blocking of known IoCs is advised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.