RondoDoX Botnet Weaponizing a Critical React2Shell Vulnerability to Deploy Malware
A threat group has escalated its operations by exploiting recent vulnerabilities in web applications and Internet of Things (IoT) devices.
A threat group has escalated its operations by exploiting recent vulnerabilities in web applications and Internet of Things (IoT) devices.
The RondoDoX botnet, monitored over a nine-month period from March to December 2025, showcases a strategic approach to compromising enterprise systems.
The malware employs a multi-stage infection process that initiates with scanning for vulnerabilities and progresses to deploying cryptominers and botnet payloads across various network environments.
The campaign includes three phases, each increasing in complexity. Initially, vulnerabilities were manually tested on several platforms.
By April 2025, automated daily scans targeted multiple web frameworks. The final phase, starting in July 2025, involved hourly attacks, highlighting the group's dedication to exploiting and compromising infrastructure.
CloudSEK analysts identified the malware during routine scans, revealing six confirmed command-and-control servers. At least ten botnet variants were active, with command logs detailing the attack timeline.
A threat group has escalated its operations by exploiting recent vulnerabilities in web applications and Internet of Things (IoT) devices.
In December 2025, threat actors began exploiting a Next.js vulnerability to deploy React2Shell payloads.
The attack chain starts with identifying vulnerable servers through remote code execution testing, followed by the deployment of ELF binaries that download malicious payloads from command-and-control infrastructure.
The malware exhibits advanced persistence and evasion capabilities, establishing persistence via cron job configuration and terminating competing malware to control system resources.
The payload includes cryptominers and frameworks for sustained control over compromised hosts. The botnet supports x86, x86_64, MIPS, ARM, and PowerPC architectures, with various download protocols ensuring payload delivery across enterprise environments.
Organizations with internet-facing routers, cameras, and applications running Next.js Server Actions are at risk. Defensive measures include:
Network segmentation Immediate patching of vulnerable applications Web Application Firewall deployment Continuous monitoring for suspicious activities in temporary directories
Blocking identified command-and-control infrastructure at perimeter firewalls offers critical short-term protection.
Based on reporting by Cyber Security News.
