Cybersecurity researchers have revealed details of a persistent nine-month campaign targeting Internet of Things (IoT) devices and web applications to integrate them into a botnet known as RondoDox.
See also: Kimwolf Botnet has infected 1.8 million Android devices

Since December 2025, this activity has been observed exploiting the recently disclosed React2Shell vulnerability (CVE-2025-55182, CVSS score: 10.0) as an initial access point, according to CloudSEK.
React2Shell is a critical security vulnerability in React Server Components (RSC) and Next.js that could allow unauthenticated attackers to achieve remote code execution on vulnerable devices. Statistics from the Shadowserver Foundation show that approximately 90,300 instances remain vulnerable to the vulnerability as of December 31, 2025, with 68,400 instances located in the U.S., followed by Germany (4,300), France (2,800), and India (1,500).
RondoDox, which emerged in early 2025, has expanded its reach by adding new N-day security vulnerabilities to its arsenal, including CVE-2023-1389 and CVE-2025-24893. The React2Shell exploit for botnet propagation was previously reported by Darktrace, Kaspersky, and VulnCheck.
The RondoDox botnet campaign is estimated to have gone through three distinct phases before the CVE-2025-55182 exploit:
- March – April 2025: Initial identification and manual vulnerability scanning
- April – June 2025: Daily mass vulnerability scanning in web applications like WordPress, Drupal, and Struts2, and IoT devices like Wavlink routers
- July – early December 2025: Hourly automated deployment at scale
See also: Aisuru botnet behind 29.7 Tbps DDoS attack

In the attacks detected in December 2025, malicious actors initiated scans to identify vulnerable Next.js servers, followed by attempts to install cryptocurrencies, a botnet loader and health checker, as well as a variant of the Mirai botnet on infected devices.
The botnet loader is designed to terminate competing malware and cryptocurrency miners before downloading the main bot binary from the command and control (C2) server. A variant of the tool has been found to remove known botnets, Docker-based payloads, artifacts from previous campaigns, and associated cron jobs, while also installing persistence using “/etc/crontab.”
It continuously scans /proc to list running executables and kills unbleached processes every ~45 seconds, effectively preventing re-emergence by adversaries, according to CloudSEK.
See also: Tsundere Botnet targets Windows users with gaming bait

To mitigate the risk posed by this threat, organizations are advised to update Next.js to a patched version as soon as possible, segregate all IoT devices into dedicated VLANs, deploy Web Application Firewalls (WAFs), monitor for suspicious process execution, and block known C2 infrastructure.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
