Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign Exploitation Wave Malware Activity

RondoDox edge and web exploitation

Updated 31.12.2025 16:58
Case score 60
Case score 60 Members 3 Latest activity 31.12.2025 16:58 Active exploitation Patch available
Active exploitation Patch available
Members 3 First seen 10.10.2025 22:22 Last seen 31.12.2025 16:58 Updated 31.12.2025 16:58

Overview

RondoDox has moved from router-focused exploitation into a broader **exploit-shotgun** and loader-as-a-service operation against routers, DVRs, NVRs, CCTV systems, web servers, and **Next.js** servers. The activity includes confirmed abuse of **CVE-2023-1389** on **TP-Link Archer** routers and later **CVE-2025-55182 (React2Shell)** exploitation against exposed web infrastructure. The payload chain now includes **Mirai/Morte**, a coinminer, and a loader/health-checker component, with persistence through **/etc/crontab**. Public reporting puts React2Shell exposure above **94,000 internet-exposed assets**, but compromise totals and the full reach of the botnet remain unquantified.