RondoDoX Botnet Weaponizes React2Shell
ID: 6b5c14aa-a0d5-5bf6-a158-69538b910653
STIX ID: report--6b5c14aa-a0d5-5bf6-a158-69538b910653
Feed Name: CloudSEK Blog
**Executive Summary:** CloudSEK observed a multi‑phase RondoDoX botnet campaign (March–December 2025) that combined web‑application exploitation (WordPress, Drupal, Struts2, WebLogic) and IoT targeting to deploy multi‑architecture botnet clients, coinminers and persistence loaders; a December wave actively exploited a Next.js Server Actions RCE to download and execute ELF payloads. The report includes attack timelines, confirmed C2 infrastructure and hashes, observable TTPs, and prioritized remediation guidance (Next.js patching, IoT segmentation, WAFs, and network blocks for identified C2s).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
