Thehackernews
RondoDox Botnet Targets React2Shell Flaw to Spread Malware
First seen 1 Jan 2026, 16:26 UTC
•



+7
•81.0
Export
Article Content
Browse articles
The RondoDox botnet is exploiting the React2Shell vulnerability (CVE-2025-55182) to infect vulnerable .js servers with malware and cryptominers. This ongoing campaign has been active for nine months, primarily targeting IoT devices and web applications, as reported by CloudSEK researchers.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
PowMix Botnet Targets Czech Organizations with Malicious LNK Files
RondoDox Botnet Expands by Exploiting Unpatched XWiki RCE Vulnerability
RondoDox Botnet Exploits HPE OneView Vulnerability
RondoDox Botnet Grows, Exploiting 174 Vulnerabilities via Residential IPs
RondoDox Botnet Expands by Exploiting Unpatched XWiki RCE Flaw
RondoDox Botnet Launches Attacks Exploiting HPE OneView Vulnerability