RondoDoX Botnet Abuses React2Shell Vulnerability for Malware Deployment
CloudSEK has identified a nine-month campaign by the RondoDoX botnet operation, which has been actively exploiting vulnerabilities, including the critical React2Shell vulnerability.
CloudSEK has identified a nine-month campaign by the RondoDoX botnet operation, which has been actively exploiting vulnerabilities, including the critical React2Shell vulnerability.
Analysis of command-and-control logs from March to December 2025 shows rapid adaptation by threat actors, shifting focus from traditional IoT targets to exploiting Next.js applications shortly after vulnerability disclosures.
On December 10, it was observed that RondoDoX operators changed infrastructure after reported React2Shell exploitation patterns, with new command-and-control servers appearing just three days later. CloudSEK's routine scans have detected loggers used by threat actors.
The operation targets vulnerable web applications and IoT devices through automated exploitation frameworks, deploying botnet payloads, web shells, and cryptocurrency miners across different architectures.
Phase Two: From April to June, mass vulnerability scanning targeted CMS platforms and expanded to include IoT devices.
Phase One: Starting in March 2025, manual reconnaissance was conducted, focusing on SQL injection, Java deserialization vulnerabilities, and WebLogic vulnerabilities. Phase Two: From April to June, mass vulnerability scanning targeted CMS platforms and expanded to include IoT devices. Phase Three: From July to December 2025, the Rondo botnet infrastructure was deployed, increasing attack frequency to hourly.
Following the disclosure of the React2Shell vulnerability, RondoDoX operators quickly weaponized CVE-2025-55182, executing two attack waves.
Initial operations between December 8-16 identified vulnerable Next.js servers. Wave two began on December 13, focusing on IoT botnet deployment.
New C2 infrastructure was established, distributing various payloads, including cryptocurrency miners and persistence frameworks. The "bolts" payload acts as a Linux dominance framework, ensuring persistence and eliminating competing botnet processes.
Organizations using Next.js Server Actions should conduct audits and implement strict input validation, upgrading to patched versions immediately. IoT devices should be segmented into dedicated VLANs with egress filtering, and identified C2 infrastructure should be blocked at firewalls. Behavioral monitoring should be deployed to detect persistence mechanisms before full compromise occurs.
Based on reporting by GBHackers.
