RondoDox Botnet is a malware campaign that uses a botnet to spread cryptocurrency miners and additional malware to compromised hosts.
RondoDox Botnet is a malware campaign that uses a botnet to spread cryptocurrency miners and additional malware to compromised hosts. The operation is linked to an ongoing assault on React2Shell, marking it as an active, high-visibility threat with potential for rapid propagation and payload variety.
The RondoDox botnet is exploiting the React2Shell vulnerability (CVE-2025-55182) to infect vulnerable .js servers with malware and cryptominers. This ongoing campaign has been active for nine months, primarily targeting…