{"id":10326,"date":"2026-01-01T10:00:50","date_gmt":"2026-01-01T10:00:50","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=10326"},"modified":"2026-01-01T10:00:50","modified_gmt":"2026-01-01T10:00:50","slug":"rondodox-botnet-exploits-vital-react2shell-flaw-to-hijack-iot-gadgets-and-net-servers","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=10326","title":{"rendered":"RondoDox Botnet Exploits Vital React2Shell Flaw to Hijack IoT Gadgets and Net Servers"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jan 01, 2026<\/span><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><\/span><span class=\"p-tags\">Community Safety \/ Vulnerability<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiQtdlV7ySzud6pktbmLsSyAnWoLz3a-ROUuyJ1mvoIfcbCrlQkb2dQJ9TqxDFk3dtTqO7H2XEFznwMmOoM2CEGaU41loeAh4MYXWm5L3rVdUCH4WyVZlp68Z-dTthmsTAcrS3l9LIDxrmEIYkMGDgVAQYtfXgVPes9kB2F_ilQxWd8qeK0JCJbo1JUmQ6d\/s790-rw-e365\/botnet.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiQtdlV7ySzud6pktbmLsSyAnWoLz3a-ROUuyJ1mvoIfcbCrlQkb2dQJ9TqxDFk3dtTqO7H2XEFznwMmOoM2CEGaU41loeAh4MYXWm5L3rVdUCH4WyVZlp68Z-dTthmsTAcrS3l9LIDxrmEIYkMGDgVAQYtfXgVPes9kB2F_ilQxWd8qeK0JCJbo1JUmQ6d\/s790-rw-e365\/botnet.jpg\" alt=\"RondoDox Botnet\" border=\"0\" data-original-height=\"470\" data-original-width=\"900\" title=\"RondoDox Botnet\"\/><\/a><\/div>\n<p>Cybersecurity researchers have disclosed particulars of a persistent nine-month-long marketing campaign that has focused Web of Issues (IoT) gadgets and internet purposes to enroll them right into a botnet often called RondoDox.<\/p>\n<p>As of December 2025, the exercise has been noticed leveraging the just lately disclosed <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2025\/12\/react2shell-vulnerability-actively.html\" rel=\"noopener\" target=\"_blank\">React2Shell<\/a> (CVE-2025-55182, CVSS rating: 10.0) flaw as an preliminary entry vector, CloudSEK <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.cloudsek.com\/blog\/rondodox-botnet-weaponizes-react2shell\" rel=\"noopener\" target=\"_blank\">mentioned<\/a> in an evaluation.<\/p>\n<p>React2Shell is the title assigned to a vital safety vulnerability in React Server Parts (RSC) and Subsequent.js that would enable unauthenticated attackers to realize distant code execution on vulnerable gadgets.<\/p>\n<p>In line with statistics from the Shadowserver Basis, there are about <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/dashboard.shadowserver.org\/statistics\/combined\/time-series\/?date_range=30&amp;source=http_vulnerable&amp;source=http_vulnerable6&amp;tag=cve-2025-55182%2B&amp;dataset=unique_ips&amp;limit=100&amp;group_by=geo&amp;stacking=stacked&amp;auto_update=on\" rel=\"noopener\" target=\"_blank\">90,300 situations<\/a> that stay vulnerable to the vulnerability as of December 31, 2025, out of which <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/dashboard.shadowserver.org\/statistics\/combined\/tree\/?date_range=1&amp;source=http_vulnerable&amp;source=http_vulnerable6&amp;tag=cve-2025-55182%2B&amp;data_set=count&amp;scale=log&amp;auto_update=on\" rel=\"noopener\" target=\"_blank\">68,400 situations<\/a> are situated within the U.S., adopted by Germany (4,300), France (2,800), and India (1,500).<\/p>\n<div class=\"dog_two clear\"><center class=\"cf\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.uk\/zero-trust-summit-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgqlhh16hjmE7NRyQeAR2_sLZ1uDwyQH2jkPHmDTAtveTHoIjCrfmK6JLqlZuNKOPG1RGLtwJk-ZJDwQiV-McwmzAUu1iOSwwMjs_tqI1KjcL_tCvc0M2XuKBPfJ1RXpKxnx-eGdWwM0wlNDnUYHvXr-1LZk2zRmDNLIEbYGalGQJsd6QwC0pyCrLavN0fz\/s728-e100\/threatlocker-inside-d.png\" width=\"729\" height=\"91\"\/><\/a><\/center><\/div>\n<p>RondoDox, which emerged in early 2025, has broadened its scale by including new N-day safety vulnerabilities to its arsenal, together with <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2025\/10\/researchers-warn-rondodox-botnet-is.html\" rel=\"noopener\" target=\"_blank\">CVE-2023-1389<\/a> and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2025\/11\/rondodox-exploits-unpatched-xwiki.html\" rel=\"noopener\" target=\"_blank\">CVE-2025-24893<\/a>. It is price noting that the abuse of React2Shell to unfold the botnet was beforehand highlighted by <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.darktrace.com\/blog\/react2shell-how-opportunist-attackers-exploited-cve-2025-55182-within-hours\" rel=\"noopener\" target=\"_blank\">Darktrace<\/a>, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2025\/12\/react2shell-exploitation-escalates-into.html\" rel=\"noopener\" target=\"_blank\">Kaspersky<\/a>, and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2025\/12\/critical-react2shell-flaw-added-to-cisa.html\" rel=\"noopener\" target=\"_blank\">VulnCheck<\/a>.<\/p>\n<p>The RondoDox botnet marketing campaign is assessed to have gone by three distinct phases previous to the exploitation of CVE-2025-55182 &#8211;<\/p>\n<ul>\n<li>March &#8211; April 2025 &#8211; Preliminary reconnaissance and handbook vulnerability scanning<\/li>\n<li>April &#8211; June 2025 &#8211; Every day mass vulnerability probing of internet purposes like WordPress, Drupal, and Struts2, and IoT gadgets like Wavlink routers<\/li>\n<li>July &#8211; early December 2025 &#8211; Hourly automated deployment on a large-scale<\/li>\n<\/ul>\n<p>Within the assaults detected in December 2025, the risk actors are mentioned to have initiated scans to determine weak Subsequent.js servers, adopted by makes an attempt to drop cryptocurrency miners (&#8220;\/nuts\/poop&#8221;), a botnet loader and well being checker (&#8220;\/nuts\/bolts&#8221;), and a Mirai botnet variant (&#8220;\/nuts\/x86&#8221;) on contaminated gadgets.<\/p>\n<p>&#8220;\/nuts\/bolts&#8221; is designed to terminate competing malware and coin miners earlier than downloading the principle bot binary from its command-and-control (C2) server. One variant of the device has been discovered to take away identified botnets, Docker-based payloads, artifacts left from prior campaigns, and related cron jobs, whereas additionally organising persistence utilizing &#8220;\/and many others\/crontab.&#8221;<\/p>\n<p>&#8220;It repeatedly scans \/proc to enumerate working executables and kills non-whitelisted processes each ~45 seconds, successfully stopping reinfection by rival actors,&#8221; CloudSEK mentioned.<\/p>\n<p>To mitigate the chance posed by this risk, organizations are suggested to replace Subsequent.js to a patched model as quickly as potential, section all IoT gadgets into devoted VLANs, deploy Net Software Firewalls (WAFs), monitor for suspicious course of execution, and block identified C2 infrastructure.<\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>\ue802Jan 01, 2026\ue804Ravie LakshmananCommunity Safety \/ Vulnerability Cybersecurity researchers have disclosed particulars of a persistent nine-month-long marketing campaign that has focused Web of Issues (IoT) gadgets and internet purposes to enroll them right into a botnet often called RondoDox. As of December 2025, the exercise has been noticed leveraging the just lately disclosed React2Shell (CVE-2025-55182, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":10328,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[3181,420,355,3183,2705,1119,576,6817,7195,2542,505],"class_list":["post-10326","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-botnet","tag-critical","tag-devices","tag-exploits","tag-flaw","tag-hijack","tag-iot","tag-react2shell","tag-rondodox","tag-servers","tag-web"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/10326","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=10326"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/10326\/revisions"}],"predecessor-version":[{"id":10327,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/10326\/revisions\/10327"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/10328"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=10326"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=10326"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=10326"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-13 15:25:12 UTC -->