Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign

RondoDox botnet pressure on IoT devices and web apps

Updated 03.01.2026 22:34
Case score 58
Case score 58 Members 1 Latest activity 03.01.2026 22:34
Members 1 First seen 01.01.2026 11:19 Last seen 01.01.2026 11:19 Updated 03.01.2026 22:34

Overview

RondoDox has sustained a persistent botnet campaign against exposed **IoT devices** and **web applications**, and by December 2025 it was using **React Server Components (CVE-2025-55182)** alongside other N-day flaws to reach internet-facing systems. The activity progressed from March-April reconnaissance and manual scanning to daily mass probing and hourly automated deployment, showing a more automated and scalable pattern. Defensive guidance centers on updating **Next.js** where applicable, segmenting IoT devices into VLANs, deploying WAFs, and watching for suspicious process execution or known C2 activity. Available evidence does not quantify reach, but observed activity spans the United States, Germany, France, and India and remained active in December 2025.

Signals

7 derived
CVEs/products
CVE
Victims/regions
Victim region France Victim region Germany Victim region India Victim region United States
Status
Campaign status Active
Threat context
Threat context RondoDox

Malware context

2 families · 3 tools
Tools
/nuts/bolts /nuts/poop /nuts/x86

Member happenings

1 related
Campaign RondoDox persistent IoT and web app botnet campaign
Updated 01.01.2026 11:19 Lead Contribution 58
Campaign Active

**Scattered Lapsus$ Hunters** claimed they breached **Resecurity** and stole internal chats, logs, employee data, threat intelligence reports, and a complete client list, but Resecurity says the accessed environment was a **deliberately deployed honeypot** with fake data used to monitor the actor. Resecurity says it first detected probing on **November 21, 2025**, then observed **December 2025** automation and exfiltration attempts before sharing intelligence with **law enforcement**.