Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

RondoDoX Botnet Abuses React2Shell Vulnerability for Malware Deployment

CloudSEK has identified a nine-month campaign by the RondoDoX botnet operation, which has been actively exploiting vulnerabilities, including the critical React2Shell vulnerability.

CloudSEK has identified a nine-month campaign by the RondoDoX botnet operation, which has been actively exploiting vulnerabilities, including the critical React2Shell vulnerability.

Analysis of command-and-control logs from March to December 2025 shows rapid adaptation by threat actors, shifting focus from traditional IoT targets to exploiting Next.js applications shortly after vulnerability disclosures.

On December 10, it was observed that RondoDoX operators changed infrastructure after reported React2Shell exploitation patterns, with new command-and-control servers appearing just three days later. CloudSEK's routine scans have detected loggers used by threat actors.

The operation targets vulnerable web applications and IoT devices through automated exploitation frameworks, deploying botnet payloads, web shells, and cryptocurrency miners across different architectures.

Phase Two: From April to June, mass vulnerability scanning targeted CMS platforms and expanded to include IoT devices.
Hazel Caldwell · Thehackingpost

Phase One: Starting in March 2025, manual reconnaissance was conducted, focusing on SQL injection, Java deserialization vulnerabilities, and WebLogic vulnerabilities. Phase Two: From April to June, mass vulnerability scanning targeted CMS platforms and expanded to include IoT devices. Phase Three: From July to December 2025, the Rondo botnet infrastructure was deployed, increasing attack frequency to hourly.

Following the disclosure of the React2Shell vulnerability, RondoDoX operators quickly weaponized CVE-2025-55182, executing two attack waves.

Initial operations between December 8-16 identified vulnerable Next.js servers. Wave two began on December 13, focusing on IoT botnet deployment.

Advertisement

New C2 infrastructure was established, distributing various payloads, including cryptocurrency miners and persistence frameworks. The "bolts" payload acts as a Linux dominance framework, ensuring persistence and eliminating competing botnet processes.

Organizations using Next.js Server Actions should conduct audits and implement strict input validation, upgrading to patched versions immediately. IoT devices should be segmented into dedicated VLANs with egress filtering, and identified C2 infrastructure should be blocked at firewalls. Behavioral monitoring should be deployed to detect persistence mechanisms before full compromise occurs.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories