RondoDox Botnet Exploits React2Shell Flaw in Next.js Servers

RondoDox Botnet Exploits React2Shell Flaw in Next.js Servers

First seen 31 Dec 2025, 16:25 UTC Bleepingcomputer 67% similarity 61.8

Article Content

Browse articles
ThreatCluster

The RondoDox botnet has been exploiting the React2Shell flaw (CVE-2025-55182) to infect vulnerable .js servers with malware and cryptominers. First documented by Fortinet in July 2025, the botnet targets multiple n-day vulnerabilities, including a critical RCE vulnerability in the XWiki Platform identified by VulnCheck in November 2025.

ThreatCluster AI

Community

Browse all →

Tracked Entities in This Story