Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign Exploitation Wave Malware Activity

RondoDox edge and web exploitation

Updated 31.12.2025 16:58
Case score 60
Case score 60 Members 3 Latest activity 31.12.2025 16:58
Active exploitation Patch available
Members 3 First seen 10.10.2025 22:22 Last seen 31.12.2025 16:58 Updated 31.12.2025 16:58

Overview

RondoDox has moved from router-focused exploitation into a broader **exploit-shotgun** and loader-as-a-service operation against routers, DVRs, NVRs, CCTV systems, web servers, and **Next.js** servers. The activity includes confirmed abuse of **CVE-2023-1389** on **TP-Link Archer** routers and later **CVE-2025-55182 (React2Shell)** exploitation against exposed web infrastructure. The payload chain now includes **Mirai/Morte**, a coinminer, and a loader/health-checker component, with persistence through **/etc/crontab**. Public reporting puts React2Shell exposure above **94,000 internet-exposed assets**, but compromise totals and the full reach of the botnet remain unquantified.

Signals

9 derived
Exploitation
Exploitation Active exploitation
CVEs/products
CVE CVE
Victims/regions
Victim region United States
Remediation
Remediation Patch available
Status
Campaign status Active
Threat context
Threat context Actor Morte Actor RondoDox

Malware context

4 families · 1 tools
Tools
Botshield

Member happenings

3 related
Campaign RondoDox multivector loader-as-a-service campaign
Updated 13.10.2025 13:12 Lead Contribution 56
Objective Disruption Campaign Active

The **RondoDox** botnet campaign has expanded into **multivector exploitation** and **loader-as-a-service** distribution, widening risk to **internet-exposed infrastructure** across **30+ vendors** and **50+ vulnerabilities**. The broadened reach makes exposed routers, DVRs, NVRs, CCTV systems, web servers, and other network devices more likely to be enrolled into the botnet. A detected use of **CVE-2023-1389** on **TP-Link Archer routers** shows the operation is actively abusing public-facing flaws. The added **Mirai/Morte** payload chain increases detection and remediation pressure.

Malware Activity RondoDox botnet React2Shell malware deployment against Next.js servers
Updated 31.12.2025 16:58 Scoring Support Contribution 2
Malware Botnet Platform Network Device

The **RondoDox botnet** is exploiting **CVE-2025-55182 (React2Shell)** to compromise **Next.js servers**, turning exposed systems into malware hosts and expanding botnet reach. Activity escalated in **December 2025** after scanning began on **December 8** and payload deployment followed **three days later**. The infection chain includes a **coinminer**, a **botnet loader/health checker**, and a **Mirai** variant, which increases persistence and abuse potential. The scale is significant because more than **94,000 internet-exposed assets** were reported vulnerable to React2Shell.

Exploitation Wave RondoDox edge-device exploitation wave
Updated 10.10.2025 22:22 Scoring Support Contribution 2
Exploitation Active Exploitation Patch Patch Available

**RondoDox** is broadening its **edge-device exploitation** wave, with Trend Micro reporting an **exploit shotgun** approach against **more than 50 vulnerabilities** across **over 30 vendors**. The campaign has targeted **routers**, **DVRs**, **NVRs**, **CCTV systems**, **web servers**, and other **internet-exposed network devices**, and Trend Micro observed an intrusion attempt on **June 15, 2025** exploiting **CVE-2023-1389** on **TP-Link Archer routers**. The activity has also expanded through a **loader-as-a-service** setup that co-packages **RondoDox** with **Mirai/Morte** payloads, increasing the urgency of detection and remediation.