BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

RondoDox Botnet Exploits React2Shell to Widen IoT Infections

RondoDox campaign weaponizes React2Shell to recruit 90,300 web apps and IoT devices—dropping miners, loaders and Mirai; patch Next.js and segment IoT.

  • A persistent nine-month campaign enrolled IoT devices and web apps into the RondoDox botnet using multiple vulnerabilities, including React2Shell (CVE-2025-55182).
  • About 90,300 vulnerable instances remain exposed globally, with 68,400 in the U.S.
  • The campaign used staged activity—reconnaissance, mass probing, and large-scale hourly deployment—and dropped miners, loaders, and a Mirai variant.
  • Defenses include patching Next.js, isolating IoT devices, deploying WAFs, monitoring processes, and blocking known C2 infrastructure.

Cybersecurity teams disclosed a nine-month campaign that recruited Internet of Things devices and web applications into the RondoDox botnet through late 2025. The activity used the critical React2Shell vulnerability (CVE-2025-55182) to gain remote code execution on exposed servers, CloudSEK said. The campaign also added older N-day flaws such as CVE-2023-1389 and CVE-2025-24893.

- Advertisement -

Data from the Shadowserver Foundation show roughly 90,300 instances vulnerable as of December 31, 2025, with 68,400 located in the U.S. Germany, France, and India followed in count.

Researchers mapped three phases of the campaign: March–April 2025 reconnaissance and manual scans; April–June daily mass probing of web apps (WordPress, Drupal, Struts2) and IoT devices like Wavlink routers; and July–early December large-scale automated hourly deployment. The abuse of React2Shell was previously flagged by Darktrace here and noted by other security firms.

In December 2025 infections, actors scanned for vulnerable Next.js servers and attempted to drop cryptocurrency miners and bot components at paths such as "/nuts/poop", "/nuts/bolts", and "/nuts/x86". The "/nuts/bolts" tool removes competing Malware and miners, clears prior campaign artifacts, and installs persistence via "/etc/crontab". As described by CloudSEK, "It continuously scans /proc to enumerate running executables and kills non-whitelisted processes every ~45 seconds, effectively preventing reinfection by rival actors."

Recommended mitigations include updating Next.js to patched versions, segmenting IoT devices into dedicated VLANs, deploying Web Application Firewalls, monitoring for suspicious process execution, and blocking known command-and-control infrastructure.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Ripple Gains Preliminary MiCA License in Luxembourg

Ripple received preliminary approval for a crucial EU-wide Crypto Asset Service Provider (CASP) license...

WhatsApp Spreads Malware via RMM Software Scam

WhatsApp accounts across 11 countries are being hijacked to distribute malware-laden VBScript files.The campaign...

Micron Defies Tech Selloff, Hits Record High Before Earnings

Micron (MU) stock hit a new all-time high on June 24, 2026, defying a...

Jefferies Sees Tesla Robotaxis as “Loss Centers”

Jefferies cut its Tesla price target to $375 and warned TSLA could start trading...

Ex-Ethereum Devs Launch Ethlabs to Woo Institutions

Former Ethereum Foundation contributors and firms Bitmine and Sharplink have funded a new nonprofit,...

Must Read

Top 8 Books Every Beginner Should Read About Cryptocurrency

Cryptocurrency and blockchain technology are filled with technical terms that beginners find challenging to understand. One of the best ways to learn about cryptocurrency...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading