RondoDox Botnet Campaign — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
January 1, 2026
Last Seen
January 1, 2026

RondoDox Botnet is a malware campaign that uses a botnet to spread cryptocurrency miners and additional malware to compromised hosts.

Overview

RondoDox Botnet is a malware campaign that uses a botnet to spread cryptocurrency miners and additional malware to compromised hosts. The operation is linked to an ongoing assault on React2Shell, marking it as an active, high-visibility threat with potential for rapid propagation and payload variety.

Related Threat Clusters

  • RondoDox Botnet Targets React2Shell Flaw to Spread Malware

    The RondoDox botnet is exploiting the React2Shell vulnerability (CVE-2025-55182) to infect vulnerable .js servers with malware and cryptominers. This ongoing campaign has been active for nine months, primarily targeting…

    12 articles · Updated January 1, 2026

Recent Intelligence Reports

  • React2Shell under attack: RondoDox Botnet spreads miners and malware — Securityaffairs.Co · January 1, 2026

CVSS v3.1 Breakdown