• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
TechTrendFeed
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
TechTrendFeed
No Result
View All Result

RondoDox Botnet Exploits Vital React2Shell Flaw to Hijack IoT Gadgets and Net Servers

Admin by Admin
January 1, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Jan 01, 2026Ravie LakshmananCommunity Safety / Vulnerability

RondoDox Botnet

Cybersecurity researchers have disclosed particulars of a persistent nine-month-long marketing campaign that has focused Web of Issues (IoT) gadgets and internet purposes to enroll them right into a botnet often called RondoDox.

As of December 2025, the exercise has been noticed leveraging the just lately disclosed React2Shell (CVE-2025-55182, CVSS rating: 10.0) flaw as an preliminary entry vector, CloudSEK mentioned in an evaluation.

React2Shell is the title assigned to a vital safety vulnerability in React Server Parts (RSC) and Subsequent.js that would enable unauthenticated attackers to realize distant code execution on vulnerable gadgets.

In line with statistics from the Shadowserver Basis, there are about 90,300 situations that stay vulnerable to the vulnerability as of December 31, 2025, out of which 68,400 situations are situated within the U.S., adopted by Germany (4,300), France (2,800), and India (1,500).

Cybersecurity

RondoDox, which emerged in early 2025, has broadened its scale by including new N-day safety vulnerabilities to its arsenal, together with CVE-2023-1389 and CVE-2025-24893. It is price noting that the abuse of React2Shell to unfold the botnet was beforehand highlighted by Darktrace, Kaspersky, and VulnCheck.

The RondoDox botnet marketing campaign is assessed to have gone by three distinct phases previous to the exploitation of CVE-2025-55182 –

  • March – April 2025 – Preliminary reconnaissance and handbook vulnerability scanning
  • April – June 2025 – Every day mass vulnerability probing of internet purposes like WordPress, Drupal, and Struts2, and IoT gadgets like Wavlink routers
  • July – early December 2025 – Hourly automated deployment on a large-scale

Within the assaults detected in December 2025, the risk actors are mentioned to have initiated scans to determine weak Subsequent.js servers, adopted by makes an attempt to drop cryptocurrency miners (“/nuts/poop”), a botnet loader and well being checker (“/nuts/bolts”), and a Mirai botnet variant (“/nuts/x86”) on contaminated gadgets.

“/nuts/bolts” is designed to terminate competing malware and coin miners earlier than downloading the principle bot binary from its command-and-control (C2) server. One variant of the device has been discovered to take away identified botnets, Docker-based payloads, artifacts left from prior campaigns, and related cron jobs, whereas additionally organising persistence utilizing “/and many others/crontab.”

“It repeatedly scans /proc to enumerate working executables and kills non-whitelisted processes each ~45 seconds, successfully stopping reinfection by rival actors,” CloudSEK mentioned.

To mitigate the chance posed by this risk, organizations are suggested to replace Subsequent.js to a patched model as quickly as potential, section all IoT gadgets into devoted VLANs, deploy Net Software Firewalls (WAFs), monitor for suspicious course of execution, and block identified C2 infrastructure.

Tags: BotnetCriticalDevicesExploitsFlawHijackIoTReact2ShellRondoDoxserversWeb
Admin

Admin

Next Post
The First Lego Marvel Collector’s Version Determine Is Obtainable Now

The First Lego Marvel Collector's Version Determine Is Obtainable Now

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

The right way to use Netdiscover to map and troubleshoot networks

The right way to use Netdiscover to map and troubleshoot networks

August 26, 2025
Learn how to Develop an App Like Uber in 2026

Learn how to Develop an App Like Uber in 2026

May 8, 2026
Prime AI Legacy System Modernization Firms in 2026

Prime AI Legacy System Modernization Firms in 2026

July 10, 2026
Extra gadgets, extra selection: celebrating a large yr for certification

Extra gadgets, extra selection: celebrating a large yr for certification

December 10, 2025
The Hundred Line: Final Protection Academy’s Huge Measurement Was A Large Threat – However It Paid Off

The Hundred Line: Final Protection Academy’s Huge Measurement Was A Large Threat – However It Paid Off

December 26, 2025

TechTrendFeed

Welcome to TechTrendFeed, your go-to source for the latest news and insights from the world of technology. Our mission is to bring you the most relevant and up-to-date information on everything tech-related, from machine learning and artificial intelligence to cybersecurity, gaming, and the exciting world of smart home technology and IoT.

Categories

  • Cybersecurity
  • Gaming
  • Machine Learning
  • Smart Home & IoT
  • Software
  • Tech News

Recent News

Apple stays on monitor for a glass-centric design overhaul of iPhone Professional’s line for 2027, countering rumors that led Jefferies to downgrade AAPL (Mark Gurman/Bloomberg)

Apple stays on monitor for a glass-centric design overhaul of iPhone Professional’s line for 2027, countering rumors that led Jefferies to downgrade AAPL (Mark Gurman/Bloomberg)

August 11, 2026
Android Banking Droppers Surge as Malware Operators Change Packaging Ways

Android Banking Droppers Surge as Malware Operators Change Packaging Ways

August 11, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://techtrendfeed.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT

© 2025 https://techtrendfeed.com/ - All Rights Reserved