216.73.217.22

RondoDoX Botnet Weaponizes React2Shell

· Published 29/12/2025 19:53 · Modified 29/12/2025 21:51

Export JSON

Essential information

Published
29/12/2025 19:53
Modified
29/12/2025 21:51
Tags
2025-12-29 botnet command and control cryptominer iot mirai next.js react2shell rondo rondodox vulnerability exploitation web application
Related entities
7 observables, 1 intrusion sets (apt), 5 techniques (mitre)

Description

A persistent nine-month campaign has been targeting devices and web applications. The threat actors have recently shifted to weaponizing a critical vulnerability, deploying malicious payloads like '' and cryptominers. The campaign, spanning from March to December 2025, shows quick adaptation to latest attack trends. The activity is divided into three phases: initial reconnaissance, exploitation, and deployment. The attackers have been using multiple servers and deploying various malware variants. The campaign has intensified in December 2025 with a focus on exploitation. The impact includes widespread device compromise, application risks, credential harvesting, and persistent multi-architecture threats.

External references