logo

RondoDoX Botnet Weaponizes React2Shell

ID: 6b5c14aa-a0d5-5bf6-a158-69538b910653

STIX ID: report--6b5c14aa-a0d5-5bf6-a158-69538b910653

Feed Name: CloudSEK Blog

Threat Score
78/100

Date Published: 2025-12-29

Date Updated: 2026-04-27

...
...

**Executive Summary:** CloudSEK observed a multi‑phase RondoDoX botnet campaign (March–December 2025) that combined web‑application exploitation (WordPress, Drupal, Struts2, WebLogic) and IoT targeting to deploy multi‑architecture botnet clients, coinminers and persistence loaders; a December wave actively exploited a Next.js Server Actions RCE to download and execute ELF payloads. The report includes attack timelines, confirmed C2 infrastructure and hashes, observable TTPs, and prioritized remediation guidance (Next.js patching, IoT segmentation, WAFs, and network blocks for identified C2s).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.