Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

RondoDoX Botnet Weaponizing a Critical React2Shell Vulnerability to Deploy Malware

A threat group has escalated its operations by exploiting recent vulnerabilities in web applications and Internet of Things (IoT) devices.

A threat group has escalated its operations by exploiting recent vulnerabilities in web applications and Internet of Things (IoT) devices.

The RondoDoX botnet, monitored over a nine-month period from March to December 2025, showcases a strategic approach to compromising enterprise systems.

The malware employs a multi-stage infection process that initiates with scanning for vulnerabilities and progresses to deploying cryptominers and botnet payloads across various network environments.

The campaign includes three phases, each increasing in complexity. Initially, vulnerabilities were manually tested on several platforms.

By April 2025, automated daily scans targeted multiple web frameworks. The final phase, starting in July 2025, involved hourly attacks, highlighting the group's dedication to exploiting and compromising infrastructure.

CloudSEK analysts identified the malware during routine scans, revealing six confirmed command-and-control servers. At least ten botnet variants were active, with command logs detailing the attack timeline.

A threat group has escalated its operations by exploiting recent vulnerabilities in web applications and Internet of Things (IoT) devices.
Thomas Blake · Thehackingpost

In December 2025, threat actors began exploiting a Next.js vulnerability to deploy React2Shell payloads.

The attack chain starts with identifying vulnerable servers through remote code execution testing, followed by the deployment of ELF binaries that download malicious payloads from command-and-control infrastructure.

The malware exhibits advanced persistence and evasion capabilities, establishing persistence via cron job configuration and terminating competing malware to control system resources.

The payload includes cryptominers and frameworks for sustained control over compromised hosts. The botnet supports x86, x86_64, MIPS, ARM, and PowerPC architectures, with various download protocols ensuring payload delivery across enterprise environments.

Advertisement

Organizations with internet-facing routers, cameras, and applications running Next.js Server Actions are at risk. Defensive measures include:

Network segmentation Immediate patching of vulnerable applications Web Application Firewall deployment Continuous monitoring for suspicious activities in temporary directories

Blocking identified command-and-control infrastructure at perimeter firewalls offers critical short-term protection.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories