Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign Exploitation Wave Malware Activity

RondoDox edge and web exploitation

Updated 31.12.2025 16:58
Case score 60
Members 3 First seen 10.10.2025 22:22 Latest activity 31.12.2025 16:58

Overview

RondoDox has moved from router-focused exploitation into a broader **exploit-shotgun** and loader-as-a-service operation against routers, DVRs, NVRs, CCTV systems, web servers, and **Next.js** servers. The activity includes confirmed abuse of **CVE-2023-1389** on **TP-Link Archer** routers and later **CVE-2025-55182 (React2Shell)** exploitation against exposed web infrastructure. The payload chain now includes **Mirai/Morte**, a coinminer, and a loader/health-checker component, with persistence through **/etc/crontab**. Public reporting puts React2Shell exposure above **94,000 internet-exposed assets**, but compromise totals and the full reach of the botnet remain unquantified.
Latest development Open development history 4 earlier developments RondoDox begins deploying botnet clients against Next.js servers Three days after scanning begins, RondoDox starts deploying botnet clients against vulnerable Next.js servers and stages payloads including a coinminer (/nuts/poop), a botnet loader and health checker (/nuts/bolts), and a Mirai variant (/nuts/x86).
  1. Earlier development

    RondoDox React2Shell activity and exposure totals are summarized

    RondoDox activity against React2Shell-exposed Next.js servers includes over 40 exploit attempts within six days in December, hourly IoT exploitation waves targeting Linksys and Wavlink routers, and loader behavior that removes competing botnet malware, enforces persistence via /etc/crontab, and kills non-whitelisted processes every 45 seconds; more than 94,000 internet-exposed assets were vulnerable to React2Shell as of December 30.

  2. Earlier development

    RondoDox exploits CVE-2023-1389 on TP-Link Archer routers

    Trend Micro detected a RondoDox intrusion attempt on June 15, 2025, when attackers exploited CVE-2023-1389 against TP-Link Archer routers. The flaw had already been under repeated active exploitation after its late-2022 disclosure.

  3. Earlier development

    RondoDox expands into multivector loader-as-a-service operations

    Trend Micro described RondoDox as using an exploit shotgun strategy to target more than 50 vulnerabilities across over 30 vendors and a broad set of internet-exposed infrastructure, including routers, digital video recorders, network video recorders, CCTV systems, web servers, and other network devices. The campaign also broadened distribution through a loader-as-a-service infrastructure that co-packages RondoDox with Mirai/Morte payloads, increasing detection and remediation urgency.

  4. Earlier development

    RondoDox edge-device exploitation wave

    In **May**, RondoDox began with exploitation of **one critical** and **one high-severity n-day** vulnerability in popular **DVRs** and **routers**. At that stage, the activity was narrower but already pointed at hard-to-patch edge devices.

Signals

Impact signals
Exploitation
CVEs/products
Geographic context
Remediation
Status
Threat context

Threat actor context

1 listed

Malware & tooling context

4 families · 1 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Campaign RondoDox multivector loader-as-a-service campaign
Updated 13.10.2025 13:12 Lead Contribution 56
Objective Disruption Campaign Active

The **RondoDox** botnet campaign has expanded into **multivector exploitation** and **loader-as-a-service** distribution, widening risk to **internet-exposed infrastructure** across **30+ vendors** and **50+ vulnerabilities**. The broadened reach makes exposed routers, DVRs, NVRs, CCTV systems, web servers, and other network devices more likely to be enrolled into the botnet. A detected use of **CVE-2023-1389** on **TP-Link Archer routers** shows the operation is actively abusing public-facing flaws. The added **Mirai/Morte** payload chain increases detection and remediation pressure.

Malware Activity RondoDox botnet React2Shell malware deployment against Next.js servers
Updated 31.12.2025 16:58 Scoring Support Contribution 2
Malware Botnet Platform Network Device

The **RondoDox botnet** is exploiting **CVE-2025-55182 (React2Shell)** to compromise **Next.js servers**, turning exposed systems into malware hosts and expanding botnet reach. Activity escalated in **December 2025** after scanning began on **December 8** and payload deployment followed **three days later**. The infection chain includes a **coinminer**, a **botnet loader/health checker**, and a **Mirai** variant, which increases persistence and abuse potential. The scale is significant because more than **94,000 internet-exposed assets** were reported vulnerable to React2Shell.

Exploitation Wave RondoDox edge-device exploitation wave
Updated 10.10.2025 22:22 Scoring Support Contribution 2
Exploitation Active Exploitation Patch Patch Available

**RondoDox** is broadening its **edge-device exploitation** wave, with Trend Micro reporting an **exploit shotgun** approach against **more than 50 vulnerabilities** across **over 30 vendors**. The campaign has targeted **routers**, **DVRs**, **NVRs**, **CCTV systems**, **web servers**, and other **internet-exposed network devices**, and Trend Micro observed an intrusion attempt on **June 15, 2025** exploiting **CVE-2023-1389** on **TP-Link Archer routers**. The activity has also expanded through a **loader-as-a-service** setup that co-packages **RondoDox** with **Mirai/Morte** payloads, increasing the urgency of detection and remediation.