Bleepingcomputer
RondoDox Botnet Exploits React2Shell Flaw in Next.js Servers
First seen 31 Dec 2025, 16:25 UTC
•
•67% similarity
•61.8
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The RondoDox botnet has been exploiting the React2Shell flaw (CVE-2025-55182) to infect vulnerable .js servers with malware and cryptominers. First documented by Fortinet in July 2025, the botnet targets multiple n-day vulnerabilities, including a critical RCE vulnerability in the XWiki Platform identified by VulnCheck in November 2025.
ThreatCluster AI